3 Total advisories
3 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.http4k:http4k-security-digest is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.1
CVE-2026-54148
http4k: `DigestAuthProvider.verify` did not bind to request URI
MEDIUM 6.5
CVE-2026-54147
http4k: `DigestAuthProvider.verify` ignored configured algorithm and did not bind to request URI
UNKNOWN
GHSA-c7jm-38gq-h67h
http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes