Vendor
high
advisory
Unbounded Gzip Decompression Denial of Service in http4k
1 TTPThe http4k library fails to limit the size of decompressed gzip data, allowing unauthenticated remote attackers to trigger JVM heap exhaustion via small, highly compressed payloads.
http4k-core
denial-of-service
vulnerability
web-server
1t
high
advisory
Authentication Bypass in http4k-security-digest via Digest URI Replay
The http4k-security-digest library fails to validate the URI parameter in Digest authentication responses, enabling attackers to replay captured authentication credentials against unauthorized endpoints within the same realm.
http4k-security-digest