CVE-2026-100724

CVE-2026-100724 published: http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains) matching on the Host header by default in reverseProxy() and reverseProxyRouting() when dispatching to configured virtual hosts. If these function...

View full NVD advisory → ← Back to CVE watch