Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
lightbend akka http vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2018-16131
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x up to and including 10.1.4 and 10.0.x up to and including 10.0.13 allow remote malicious users to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.
Lightbend Akka Http
6.5
CVSSv3
CVE-2021-23339
This affects all versions prior to 10.1.14 and from 10.2.0 to 10.2.4 of package com.typesafe.akka:akka-http-core. It allows multiple Transfer-Encoding headers.
Lightbend Akka-http
5.5
CVSSv3
CVE-2023-33251
When Akka HTTP prior to 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linux or UNIX, a similar issue to CVE-2022-41946.
Lightbend Akka Http
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-36920
buffer overflow
CVE-2024-36913
CVE-2024-5497
CVE-2024-23917
CVE-2024-4956
server-side request forgery
CVE-2024-35468
SSTI
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started