MEDIUM 5.9 Maven

Http4s: DigestAuth allows replay of captured requests

GHSA-9xww-74xv-gjfp · CVE-2026-69206

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The DigestAuth replay defence stores lastNc + 1 rather than the nonce-count (nc) value it just accepted. When a legitimate client sends non-contiguous nc values (parallel or retried requests, as browsers do), the server's counter lags behind the highest nc seen, and a captured Authorization header can be replayed multiple times.

Impact

A passive observer can turn one captured Digest-authenticated request into several replayed authenticated (state-changing) requests, defeating the core
replay protection Digest provides over Basic.

Preconditions

  • Application uses DigestAuth.
  • Attacker can passively observe at least one legitimate digest request.
  • Legitimate client emits an nc more than one greater than the last, for instance from a parallel or retried request.

Workarounds

  • Deploy over TLS so requests cannot be captured.

Ready to move

Start Securing

Free, no credit card | First findings in minutes