CVE-2021-42697
02.11.2021, 22:15
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.Enginsight
Vendor | Product | Version |
---|---|---|
akka | http_server | 10.1.0 ≤ 𝑥 < 10.1.15 |
akka | http_server | 10.2.0 ≤ 𝑥 < 10.2.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References