CVE-2018-16131 — Uncontrolled Resource Consumption in Akka Http
Severity
7.5HIGHNVD
EPSS
1.3%
top 19.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 30
Latest updateOct 22
Description
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages1 packages
Patches
🔴Vulnerability Details
3OSV▶
High severity vulnerability that affects com.typesafe.akka:akka-http-core_2.11 and com.typesafe.akka:akka-http-core_2.12↗2018-10-22
GHSA▶
High severity vulnerability that affects com.typesafe.akka:akka-http-core_2.11 and com.typesafe.akka:akka-http-core_2.12↗2018-10-22
CVEList▶
CVE-2018-16131: The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10↗2018-08-30