CVE-2026-100725
http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping rules for the cookie domain, path, and Secure attributes. When a single BasicCookieStorage instance is used to talk to more than one origin or scheme, cookies stored for one origin can be sent to other origins, and cookies marked Secure can be sent over plain HTTP, potentially disclosing session cookies or other sensitive values to unauthorized hosts or network observers. Clients that use a storage instance for a single origin are not affected.
CVSS
- Version: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Base score: 8.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.24%
- Percentile among all scored CVEs: 14
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access65 % - Primary impact
T1005Data from Local Systemcollection75 % - Secondary impact
T1212Exploitation for Credential Accesscredential access70 %
AV:N sin autenticación permite explotación remota de la aplicación (T1190). VC:H indica acceso a datos sensibles (cookies de sesión) vía CWE-200 (fuga de información), impactando lectura de datos (T1005) y credenciales (T1212).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-200
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-100725",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-100725",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-28T16:47:23.806596Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.2,
"exploitabilityScore": 2.2
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.3,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "disclosure@vulncheck.com",
"affectedData": [
{
"vendor": "http4k",
"product": "http4k",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "6.48.0.0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "6.48.0.0",
"versionType": "custom"
}
],
"packageURL": "pkg:maven/org.http4k/http4k-core",
"defaultStatus": "unaffected"
},
{
"vendor": "http4k",
"product": "http4k",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "5.42.0.0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "5.42.0.0",
"versionType": "custom"
}
],
"packageURL": "pkg:maven/org.http4k/http4k-core",
"defaultStatus": "unaffected"
},
{
"vendor": "http4k",
"product": "http4k",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "4.51.0.0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "4.51.0.0",
"versionType": "custom"
}
],
"packageURL": "pkg:maven/org.http4k/http4k-core",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-09-27T02:17:20.760",
"references": [
{
"url": "https://github.com/http4k/http4k/commit/6a9b44d743",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://github.com/http4k/http4k/security/advisories/GHSA-pr33-38xx-6r26",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://www.vulncheck.com/advisories/http4k-before-6.48.0.0-cookie-scoping-bypass-via-basiccookiestorage",
"source": "disclosure@vulncheck.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (client-side cookie store used by ClientFilters.Cookies) that does not enforce RFC 6265 scoping rules for the cookie domain, path, and Secure attributes. When a single BasicCookieStorage instance is used to talk to more than one origin or scheme, cookies stored for one origin can be sent to other origins, and cookies marked Secure can be sent over plain HTTP, potentially disclosing session cookies or other sensitive values to unauthorized hosts or network observers. Clients that use a storage instance for a single origin are not affected."
}
],
"lastModified": "2026-09-30T17:32:07.107",
"sourceIdentifier": "disclosure@vulncheck.com"
}