PT-2026-99452 · Http4K · Http4K

CVE-2026-100725

·

Published

2026-06-19

·

Updated

2026-09-27

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions http4k versions prior to 6.48.0.0 http4k version 5.42.0.0 http4k version 4.51.0.0
Description The BasicCookieStorage (a client-side cookie store used by ClientFilters.Cookies) fails to enforce RFC 6265 scoping rules regarding the cookie domain, path, and Secure attributes. If a single BasicCookieStorage instance is used to communicate with multiple origins or schemes, cookies intended for one origin may be sent to others. Additionally, cookies marked as Secure may be transmitted over plain HTTP, which could lead to the disclosure of session cookies or other sensitive data to unauthorized hosts or network observers.
Recommendations Update http4k to a version later than 6.48.0.0. Update http4k to a version later than 5.42.0.0. Update http4k to a version later than 4.51.0.0. As a temporary mitigation, ensure that a separate BasicCookieStorage instance is used for each unique origin to prevent cross-origin cookie leakage.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100725
GHSA-PR33-38XX-6R26

Affected Products

Http4K