Akka records
5 published records for vendor akka.
Researcher profile
- Entered KEV
- 1 · 20%
- Weaponized
- 1 · 20%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-287 Improper Authentication1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-502 Deserialization of Untrusted Data1
- CWE-674 Uncontrolled Recursion1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
41Plan | CVE-2021-42697Proof of concept | Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote atakka · http server · CWE-674 | High7.5 | — | 36.1% | Nov 2, 2021 |
34Monitor | CVE-2017-1000034No exploit | Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code executiakka · akka · CWE-502 | High8.1 | — | 6.2% | Jul 17, 2017 |
30Monitor | CVE-2017-1000118No exploit | Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Serviceakka · http server · CWE-119 | High7.5 | — | 1.1% | Oct 4, 2017 |
26Monitor | CVE-2025-46548No exploit | Apache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authenticatioapache · pekko management · CWE-287 | Medium6.5 | — | 0.7% | Jun 3, 2025 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2021-4269741Plan
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote at
HighCVSS 7.5Proof of conceptEPSS 36%akka · http serverNov 2, 2021
- CVE-2017-100003434Monitor
Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code executi
HighCVSS 8.1No exploitEPSS 6%akka · akkaJul 17, 2017
- CVE-2017-100011830Monitor
Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service
HighCVSS 7.5No exploitEPSS 1%akka · http serverOct 4, 2017
- CVE-2025-4654826Monitor
Apache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authenticatio
MediumCVSS 6.5No exploitEPSS 1%apache · pekko managementJun 3, 2025