CVE-2026-69206
Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, DigestAuth replay protection records lastNc plus one instead of the highest nonce-count value it has accepted. When a legitimate client sends noncontiguous nc values because of parallel or retried requests, the stored counter remains below the accepted maximum, allowing a passive observer to replay a captured Authorization header multiple times. Successful replays execute authenticated requests, including state-changing operations, as the captured user. This issue is fixed in versions 0.23.35 and 1.0.0-M47.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS probability
- 0.33%
- CWE
- CWE-294
- Published
- 2026-09-15
- Last modified
- 2026-09-16
Affected products
- http4s http4s
- http4s http4s
Weakness type
Related vulnerabilities
- CVE-2026-65905 — Apache Tomcat: Limited replay attack possible with DIGEST authentication
- CVE-2024-38438 — D-Link - CWE-294: Authentication Bypass by Capture-replay
- CVE-2025-6030 — Autoeastern Smart Keyless Entry System Replay Attack
- CVE-2025-6029 — KIA-branded Aftermarket Generic Smart Keyless Entry System Replay Attack
- CVE-2023-0014 — Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
- CVE-2025-36593 — Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerab
- CVE-2024-43099 — AutomationDirect DirectLogic H2-DM1E Authentication Bypass by Capture-replay
- CVE-2024-12839 — Changing Information Technology CGFIDO - Authentication Bypass