CVE-2018-16131: Lightbend Akka HTTP
High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.
Affected products
- Lightbend Akka HTTP: from 10.0.0, up to and including 10.0.13; from 10.1.0, up to and including 10.1.4
Published 2018-08-30. Last modified 2026-06-17.