{"id":"CVE-2026-69206","aliases":["GHSA-9xww-74xv-gjfp"],"url":"https://o3.security/vulnerability/CVE-2026-69206","summary":"Http4s: DigestAuth allows replay of captured requests","details":"Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records lastNc plus one instead of the highest nonce-count value it has accepted. When a legitimate client sends noncontiguous nc values because of parallel or retried requests, the stored counter remains below the accepted maximum, allowing a passive observer to replay a captured Authorization header multiple times. Successful replays execute authenticated requests, including state-changing operations, as the captured user. This issue is fixed in versions 0.23.35 and 1.0.0-M47.","published":"2026-09-15T19:29:40.341Z","modified":"2026-09-16T11:45:23.990705630Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"org.http4s:http4s-ember-core_2.12","fixedVersion":"0.23.35"},{"ecosystem":"Maven","name":"org.http4s:http4s-ember-core_2.13","fixedVersion":"0.23.35"},{"ecosystem":"Maven","name":"org.http4s:http4s-ember-core_3","fixedVersion":"0.23.35"},{"ecosystem":"Maven","name":"org.http4s:http4s-ember-core_2.13","fixedVersion":"1.0.0-M47"},{"ecosystem":"Maven","name":"org.http4s:http4s-ember-core_3","fixedVersion":"1.0.0-M47"}],"fix":{"url":"https://github.com/http4s/http4s/commit/7f065101c45f3d86bc105e8fc6323c2c4a11471f","label":"http4s/http4s@7f06510"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69206.json"},{"type":"FIX","url":"https://github.com/http4s/http4s/commit/7f065101c45f3d86bc105e8fc6323c2c4a11471f"},{"type":"WEB","url":"https://github.com/http4s/http4s/releases/tag/v0.23.35"},{"type":"WEB","url":"https://github.com/http4s/http4s/releases/tag/v1.0.0-M47"},{"type":"ADVISORY","url":"https://github.com/http4s/http4s/security/advisories/GHSA-9xww-74xv-gjfp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-69206"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T11:45:23.990705630Z"}}