PT-2026-99451 · Http4K · Http4K
CVE-2026-100724
·
Published
2026-06-19
·
Updated
2026-09-27
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
http4k versions prior to 6.49.0.0
http4k version 5.42.0.0
http4k version 4.51.0.0
Description
When dispatching to configured virtual hosts, the
reverseProxy() and reverseProxyRouting() functions use substring matching on the Host header by default. If these functions are used as a public-facing inbound HTTP handler with multiple configured virtual hosts, a remote attacker can provide a Host header containing a configured vhost name to be routed to that vhost, which allows bypassing routing-based authorization.Recommendations
Update to a version later than 6.49.0.0, 5.42.0.0, and 4.51.0.0.
As a temporary mitigation, restrict the use of
reverseProxy() and reverseProxyRouting() in public-facing inbound HTTP handlers that manage multiple virtual hosts.Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Http4K