← Back

CVE-2018-16131

nvd nist
Published: Aug 30, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.

Affected (2)

Products: Lightbend: Akka Http
1 product
Akka Http
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Lightbend
From 10.0.0 to 10.0.13
From 10.1.0 to 10.1.4

References (8)

Timeline

No history available yet.