Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
By Recent Activity
akka-http vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2021-23339
This affects all versions of package com.typesafe.akka:akka-http-core. It allows multiple Transfer-Encoding headers....
Lightbend Akka-http -
NA
CVE-2020-28452
This affects the package com.softwaremill.akka-http-session:core_2.12 from 0 and before 0.6.1; all versions of package com.softwaremill.akka-http-session:core_2.11; the package com.softwaremill.akka-http-session:core_2.13 from 0 and before 0.6.1. CSRF protection can be bypassed...
Softwaremill Akka-http-session
445
VMScore
CVE-2017-1000118
Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service...
Akka Http Server
694
VMScore
CVE-2018-16131
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb....
Lightbend Akka Http
NA
CVE-2020-7780
This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.11 before 0.5.11. For older versions, endpoints protected by...
Softwaremill Akka-http-session
828
VMScore
CVE-2017-1000034
Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem....
Akka Akka
Akka Akka 2.5
1 Github repository available
570
VMScore
CVE-2018-16115
Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error. A random number generator is used in Akka Remoting for TLS (both classic and Artery Remoting). Akka allows configuration of custom random number generators. For historical...
Lightbend Akka
605
VMScore
CVE-2010-0010
Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size...
Apache Http Server 0.8.11
Apache Http Server 0.8.14
Apache Http Server 1.0
Apache Http Server 1.0.3
Apache Http Server 1.0.5
Apache Http Server 1.1
Apache Http Server 1.2
Apache Http Server 1.2.4
Apache Http Server 1.2.5
Apache Http Server 1.2.6
Apache Http Server 1.3
Apache Http Server 1.3.0
Apache Http Server 1.3.1
Apache Http Server 1.3.2
Apache Http Server 1.3.3
Apache Http Server 1.3.4
Apache Http Server 1.3.10
Apache Http Server 1.3.11
Apache Http Server 1.3.12
Apache Http Server 1.3.13
Apache Http Server 1.3.14
Apache Http Server 1.3.15
Apache Http Server 1.3.17
Apache Http Server 1.3.18
Apache Http Server 1.3.19
Apache Http Server 1.3.20
Apache Http Server 1.3.22
Apache Http Server 1.3.23
Apache Http Server 1.3.24
Apache Http Server 1.3.25
Apache Http Server 1.3.26
Apache Http Server 1.3.27
Apache Http Server 1.3.28
Apache Http Server 1.3.29
Apache Http Server 1.3.30
Apache Http Server 1.3.31
Apache Http Server 1.3.32
Apache Http Server 1.3.33
Apache Http Server 1.3.34
Apache Http Server 1.3.35
Apache Http Server 1.3.36
Apache Http Server 1.3.37
Apache Http Server 1.3.38
Apache Http Server 1.3.39
Apache Http Server 1.3.40
Apache Http Server
383
VMScore
CVE-2016-4975
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache...
Apache Http Server 2.2.0
Apache Http Server 2.2.2
Apache Http Server 2.2.3
Apache Http Server 2.2.4
Apache Http Server 2.2.6
Apache Http Server 2.2.8
Apache Http Server 2.2.9
Apache Http Server 2.2.10
Apache Http Server 2.2.11
Apache Http Server 2.2.12
Apache Http Server 2.2.13
Apache Http Server 2.2.14
Apache Http Server 2.2.15
Apache Http Server 2.2.16
Apache Http Server 2.2.17
Apache Http Server 2.2.18
Apache Http Server 2.2.19
Apache Http Server 2.2.20
Apache Http Server 2.2.21
Apache Http Server 2.2.22
Apache Http Server 2.2.23
Apache Http Server 2.2.24
Apache Http Server 2.2.25
Apache Http Server 2.2.26
Apache Http Server 2.2.27
Apache Http Server 2.2.29
Apache Http Server 2.2.31
Apache Http Server 2.4.1
Apache Http Server 2.4.2
Apache Http Server 2.4.3
Apache Http Server 2.4.4
Apache Http Server 2.4.6
Apache Http Server 2.4.7
Apache Http Server 2.4.9
Apache Http Server 2.4.10
Apache Http Server 2.4.12
Apache Http Server 2.4.16
Apache Http Server 2.4.17
Apache Http Server 2.4.18
Apache Http Server 2.4.20
Apache Http Server 2.4.23
445
VMScore
CVE-2004-0263
PHP 4.3.4 and earlier in Apache 1.x and 2.x (mod_php) can leak global variables between virtual hosts that are handled by the same Apache child process but have different settings, which could allow remote attackers to obtain sensitive information....
Apache Http Server 1.0
Apache Http Server 1.0.2
Apache Http Server 1.0.3
Apache Http Server 1.0.5
Apache Http Server 1.1
Apache Http Server 1.1.1
Apache Http Server 1.2
Apache Http Server 1.2.5
Apache Http Server 1.3
Apache Http Server 1.3.1
Apache Http Server 1.3.3
Apache Http Server 1.3.4
Apache Http Server 1.3.6
Apache Http Server 1.3.7
Apache Http Server 1.3.9
Apache Http Server 1.3.11
Apache Http Server 1.3.12
Apache Http Server 1.3.14
Apache Http Server 1.3.17
Apache Http Server 1.3.18
Apache Http Server 1.3.19
Apache Http Server 1.3.20
Apache Http Server 1.3.22
Apache Http Server 1.3.23
Apache Http Server 1.3.24
Apache Http Server 1.3.25
Apache Http Server 1.3.26
Apache Http Server 1.3.27
Apache Http Server 1.3.28
Apache Http Server 1.3.29
Apache Http Server 2.0
Apache Http Server 2.0.9
Apache Http Server 2.0.28
Apache Http Server 2.0.32
Apache Http Server 2.0.35
Apache Http Server 2.0.36
Apache Http Server 2.0.37
Apache Http Server 2.0.38
Apache Http Server 2.0.39
Apache Http Server 2.0.40
Apache Http Server 2.0.41
Apache Http Server 2.0.42
Apache Http Server 2.0.43
Apache Http Server 2.0.44
Apache Http Server 2.0.45
Apache Http Server 2.0.46
Apache Http Server 2.0.47
Apache Http Server 2.0.48
Ibm Http Server 1.3.19
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2021-22183
CVE-2021-25252
CVE-2021-21972
CVE-2021-26858
information disclosure
CVE-2021-22182
gitlab
CVE-2020-29047
privilege
template injection
1
2
3
4
5
NEXT »