CVE-2017-1000034: Akka

High severity, CVSS 8.1. EPSS: 6.2% chance of exploitation in the next 30 days.

Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.

Affected products

  • Akka Akka: up to and including 2.4.16; version 2.5 only

Published 2017-07-17. Last modified 2026-06-17.