PT-2026-99451 · Http4K · Http4K

CVE-2026-100724

·

Published

2026-06-19

·

Updated

2026-09-27

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions http4k versions prior to 6.49.0.0 http4k version 5.42.0.0 http4k version 4.51.0.0
Description When dispatching to configured virtual hosts, the reverseProxy() and reverseProxyRouting() functions use substring matching on the Host header by default. If these functions are used as a public-facing inbound HTTP handler with multiple configured virtual hosts, a remote attacker can provide a Host header containing a configured vhost name to be routed to that vhost, which allows bypassing routing-based authorization.
Recommendations Update to a version later than 6.49.0.0, 5.42.0.0, and 4.51.0.0. As a temporary mitigation, restrict the use of reverseProxy() and reverseProxyRouting() in public-facing inbound HTTP handlers that manage multiple virtual hosts.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100724
GHSA-JRPC-7VXP-69P6

Affected Products

Http4K