Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.typesafe.akka/akka-http
  4. ›
  5. CVE-2021-42697

CVE-2021-42697: Uncontrolled Recursion in Akka HTTP

May 24, 2022 (updated June 21, 2022)

Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.

References

  • packetstormsecurity.com/files/167018/Akka-HTTP-10.1.14-Denial-Of-Service.html
  • akka.io/blog/
  • akka.io/blog/news/2021/11/02/akka-http-10.2.7-released
  • akka.io/blog/news/2021/11/22/akka-http-10.1.15-released
  • doc.akka.io/docs/akka-http/current/security/2021-CVE-2021-42697-stack-overflow-parsing-user-agent.html
  • github.com/advisories/GHSA-3hw2-h67c-wq66
  • nvd.nist.gov/vuln/detail/CVE-2021-42697

Code Behaviors & Features

Detect and mitigate CVE-2021-42697 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 10.1.0 up to 10.2.6

Fixed versions

  • 10.2.7

Solution

Upgrade to version 10.2.7 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Source file

maven/com.typesafe.akka/akka-http/CVE-2021-42697.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:45 +0000.