MidnightBSD

Advisories for akka

CVE-2017-1000034 HIGH

Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-502,

Products Affected

Vendor Product Version
akka akka 2.5
akka akka *
CVE-2017-1000118 MEDIUM

Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
akka http_server *
CVE-2021-42697 MEDIUM

Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-674,

Products Affected

Vendor Product Version
akka http_server *
CVE-2023-44487

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 3.9 3.6

Products Affected

Vendor Product Version
f5 big-ip_link_controller 17.1.0
apache tomcat 11.0.0
redhat openshift -
debian debian_linux 11.0
openresty openresty *
f5 big-ip_ssl_orchestrator *
microsoft windows_server_2019 -
redhat ansible_automation_platform 2.0
redhat cost_management -
debian debian_linux 12.0
cisco prime_cable_provisioning *
nghttp2 nghttp2 *
f5 big-ip_policy_enforcement_manager *
redhat openshift_data_science -
f5 big-ip_webaccelerator *
cisco iot_field_network_director *
konghq kong_gateway *
redhat jboss_a-mq_streams -
linecorp armeria *
redhat decision_manager 7.0
redhat certification_for_red_hat_enterprise_linux 8.0
f5 big-ip_global_traffic_manager 17.1.0
f5 big-ip_next_service_proxy_for_kubernetes *
apache tomcat *
nodejs node.js *
redhat enterprise_linux 8.0
f5 big-ip_ddos_hybrid_defender 17.1.0
redhat jboss_enterprise_application_platform 6.0.0
cisco prime_access_registrar *
linkerd linkerd 2.13.0
f5 big-ip_domain_name_system 17.1.0
cisco enterprise_chat_and_email -
f5 big-ip_application_visibility_and_reporting 17.1.0
linkerd linkerd 2.14.0
cisco unified_contact_center_enterprise_-_live_data_server *
facebook proxygen *
envoyproxy envoy 1.27.0
cisco secure_malware_analytics *
golang http2 *
kazu-yamamoto http2 *
cisco ultra_cloud_core_-_policy_control_function 2024.01.0
eclipse jetty *
redhat openshift_container_platform_assisted_installer -
f5 nginx_ingress_controller *
cisco ultra_cloud_core_-_session_management_function *
redhat build_of_quarkus -
redhat quay 3.0.0
f5 big-ip_link_controller *
cisco ios_xe *
redhat ceph_storage 5.0
f5 big-ip_local_traffic_manager *
cisco ultra_cloud_core_-_serving_gateway_function *
cisco crosswork_data_gateway 5.0
redhat advanced_cluster_security 4.0
f5 big-ip_ssl_orchestrator 17.1.0
f5 big-ip_access_policy_manager 17.1.0
f5 big-ip_analytics 17.1.0
f5 big-ip_next 20.0.1
cisco firepower_threat_defense *
microsoft windows_11_22h2 *
redhat node_healthcheck_operator -
f5 big-ip_carrier-grade_nat *
cisco telepresence_video_communication_server *
cisco connected_mobile_experiences *
redhat openshift_gitops -
microsoft windows_server_2022 -
cisco business_process_automation *
traefik traefik *
envoyproxy envoy 1.25.9
caddyserver caddy *
fedoraproject fedora 38
dena h2o *
cisco crosswork_data_gateway *
redhat migration_toolkit_for_applications 6.0
f5 big-ip_local_traffic_manager 17.1.0
f5 big-ip_advanced_web_application_firewall 17.1.0
cisco crosswork_situation_manager -
cisco nx-os *
redhat jboss_fuse 6.0.0
cisco fog_director *
cisco unified_contact_center_enterprise -
grpc grpc 1.57.0
redhat migration_toolkit_for_virtualization -
redhat openshift_distributed_tracing -
apple swiftnio_http/2 *
f5 big-ip_fraud_protection_service *
redhat advanced_cluster_management_for_kubernetes 2.0
ietf http 2.0
microsoft cbl-mariner *
f5 big-ip_policy_enforcement_manager 17.1.0
redhat enterprise_linux 9.0
linkerd linkerd 2.14.1
akka http_server *
redhat network_observability_operator -
redhat build_of_optaplanner 8.0
redhat node_maintenance_operator -
redhat openstack_platform 16.1
f5 nginx_plus r29
traefik traefik 3.0.0
redhat run_once_duration_override_operator -
microsoft windows_10_22h2 *
linkerd linkerd *
redhat jboss_data_grid 7.0.0
microsoft asp.net_core *
varnish_cache_project varnish_cache *
f5 big-ip_advanced_web_application_firewall *
f5 nginx_plus r30
redhat openshift_sandboxed_containers -
f5 big-ip_advanced_firewall_manager 17.1.0
f5 big-ip_carrier-grade_nat 17.1.0
redhat service_telemetry_framework 1.5
redhat jboss_fuse 7.0.0
f5 big-ip_websafe 17.1.0
redhat jboss_enterprise_application_platform 7.0.0
cisco secure_web_appliance_firmware *
cisco unified_contact_center_management_portal -
f5 big-ip_application_visibility_and_reporting *
redhat openshift_virtualization 4
redhat jboss_core_services -
f5 big-ip_global_traffic_manager *
f5 nginx_plus *
f5 big-ip_ddos_hybrid_defender *
cisco ultra_cloud_core_-_policy_control_function *
redhat jboss_a-mq 7
redhat openshift_container_platform 4.0
redhat logging_subsystem_for_red_hat_openshift -
redhat openshift_api_for_data_protection -
redhat openstack_platform 17.1
f5 big-ip_application_security_manager 17.1.0
f5 big-ip_application_acceleration_manager 17.1.0
cisco ios_xr *
istio istio *
redhat integration_camel_k -
redhat openshift_pipelines -
redhat openshift_dev_spaces -
f5 big-ip_fraud_protection_service 17.1.0
redhat advanced_cluster_security 3.0
netapp oncommand_insight -
cisco prime_infrastructure *
f5 big-ip_advanced_firewall_manager *
redhat support_for_spring_boot -
redhat 3scale_api_management_platform 2.0
grpc grpc *
cisco data_center_network_manager -
cisco crosswork_zero_touch_provisioning *
amazon opensearch_data_prepper *
redhat openstack_platform 16.2
netapp astra_control_center -
envoyproxy envoy 1.24.10
redhat web_terminal -
fedoraproject fedora 37
f5 big-ip_analytics *
f5 big-ip_websafe *
redhat migration_toolkit_for_containers -
jenkins jenkins *
redhat fence_agents_remediation_operator -
redhat openshift_secondary_scheduler_operator -
redhat self_node_remediation_operator -
cisco unified_contact_center_domain_manager -
microsoft windows_10_21h2 *
cisco secure_dynamic_attributes_connector *
envoyproxy envoy 1.26.4
golang networking *
microsoft windows_10_1809 *
cisco expressway *
redhat cert-manager_operator_for_red_hat_openshift -
redhat certification_for_red_hat_enterprise_linux 9.0
redhat service_interconnect 1.0
f5 nginx *
projectcontour contour *
apache apisix *
redhat openshift_serverless -
microsoft visual_studio_2022 *
redhat integration_camel_for_spring_boot -
redhat openshift_service_mesh 2.0
apache solr *
f5 big-ip_webaccelerator 17.1.0
redhat cryostat 2.0
cisco unified_attendant_console_advanced -
microsoft windows_10_1607 *
debian debian_linux 10.0
redhat openshift_developer_tools_and_services -
redhat process_automation 7.0
microsoft windows_server_2016 -
f5 big-ip_application_security_manager *
netty netty *
redhat satellite 6.0
microsoft azure_kubernetes_service *
golang go *
linkerd linkerd 2.13.1
apache traffic_server *
f5 big-ip_domain_name_system *
redhat machine_deletion_remediation_operator -
redhat enterprise_linux 6.0
f5 big-ip_application_acceleration_manager *
redhat integration_service_registry -
redhat single_sign-on 7.0
microsoft windows_11_21h2 *
microsoft .net *
cisco prime_network_registrar *
f5 big-ip_access_policy_manager *
CVE-2025-46548

If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. Akka was affected by the same issue and has released the fix in version 1.6.1.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N 3.9 2.5

Products Affected

Vendor Product Version
akka akka_management *
apache pekko_management *