First published: Thu Aug 30 2018(Updated: )
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lightbend Akka HTTP | >=10.0.0<=10.0.13 | |
Lightbend Akka HTTP | >=10.1.0<=10.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16131 is a vulnerability in Lightbend Akka HTTP that allows remote attackers to cause a denial of service by consuming excessive memory and crashing the daemon.
The vulnerability is caused by the decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP, which can be exploited by sending a ZIP bomb that consumes excessive memory and crashes the daemon.
Lightbend Akka HTTP versions 10.0.0 through 10.0.13 and 10.1.0 through 10.1.4 are affected by CVE-2018-16131.
The severity of CVE-2018-16131 is high with a severity value of 7.5.
To mitigate the vulnerability, upgrade to Lightbend Akka HTTP version 10.0.14 or 10.1.5 or later.