CVE-2018-16131
HIGH7.5EPSS 1.3%High severity vulnerability that affects com.typesafe.akka:akka-http-core_2.11 and com.typesafe.akka:akka-http-core_2.12
Published: 10/22/2018Modified: 11/8/2023
Description
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.
Affected packages (2)
- Maven/com.typesafe.akka:akka-http-core_2.11>= 10.1.0, < 10.1.4
- Maven/com.typesafe.akka:akka-http-core_2.12>= 10.1.0, < 10.1.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (6)
- ADVISORYhttps://github.com/advisories/GHSA-9qgc-p27w-3hjg
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2018-16131
- WEBhttps://akka.io/blog/news/2018/08/30/akka-http-dos-vulnerability-found
- WEBhttps://doc.akka.io/docs/akka-http/current/security/2018-09-05-denial-of-service-via-decodeRequest.html
- WEBhttps://github.com/akka/akka-http/issues/2137
- WEBhttps://groups.google.com/forum/#!topic/akka-security/Dj7INsYWdjg