Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
akka vulnerabilities and exploits
(subscribe to this query)
8.1
CVSSv3
CVE-2017-1000034
Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.
Akka Akka 2.5
Akka Akka
7.5
CVSSv3
CVE-2023-31442
In Lightbend Akka prior to 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictable DNS transaction IDs when resolving DNS records, making DNS resolution subject to poisoning by an attacker. If the application performing...
Lightbend Akka Discovery
Lightbend Akka Actor
9.1
CVSSv3
CVE-2018-16115
Lightbend Akka 2.5.x prior to 2.5.16 allows message disclosure and modification because of an RNG error. A random number generator is used in Akka Remoting for TLS (both classic and Artery Remoting). Akka allows configuration of custom random number generators. For historical rea...
Lightbend Akka
7.5
CVSSv3
CVE-2021-42697
Akka HTTP 10.1.x prior to 10.1.15 and 10.2.x prior to 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote malicious user to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.
Akka Http Server
7.5
CVSSv3
CVE-2017-1000118
Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service
Akka Http Server
7.5
CVSSv3
CVE-2018-16131
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x up to and including 10.1.4 and 10.0.x up to and including 10.0.13 allow remote malicious users to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.
Lightbend Akka Http
6.5
CVSSv3
CVE-2021-23339
This affects all versions prior to 10.1.14 and from 10.2.0 to 10.2.4 of package com.typesafe.akka:akka-http-core. It allows multiple Transfer-Encoding headers.
Lightbend Akka-http
8.8
CVSSv3
CVE-2020-7780
This affects the package com.softwaremill.akka-http-session:core_2.13 prior to 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 prior to 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 prior to 0.5.11. For older versions, endpoints protected by ra...
Softwaremill Akka-http-session
8.8
CVSSv3
CVE-2020-28452
This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and prior to 0.6.1; all versions of package com.softwaremill.akka-http-session:core_2.11; the package com.softwaremill.akka-http-session:core_2.13 from 0 and prior to 0.6.1. CSRF protection can be bypass...
Softwaremill Akka-http-session
5.5
CVSSv3
CVE-2023-33251
When Akka HTTP prior to 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linux or UNIX, a similar issue to CVE-2022-41946.
Lightbend Akka Http
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48654
CVE-2024-2757
authentication bypass
CVE-2024-3194
CVE-2024-33640
CVE-2024-21111
dos
insecure direct object reference
CVE-2024-21345
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »