CVE-2021-42697
Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42697?
CVE-2021-42697 is a vulnerability in Akka HTTP versions 10.1.x before 10.1.15 and 10.2.x before 10.2.7 that can lead to stack exhaustion while parsing HTTP headers, allowing a remote attacker to conduct a Denial of Service (DoS) attack.
How severe is CVE-2021-42697?
CVE-2021-42697 has a severity rating of 7.5 (high).
How does CVE-2021-42697 affect Akka HTTP?
CVE-2021-42697 affects Akka HTTP versions 10.1.x before 10.1.15 and 10.2.x before 10.2.7.
How can a remote attacker exploit CVE-2021-42697?
A remote attacker can exploit CVE-2021-42697 by sending a User-Agent header with deeply nested comments.
Is there a fix for CVE-2021-42697?
Yes, the fix for CVE-2021-42697 is to upgrade Akka HTTP to version 10.1.15 or 10.2.7 depending on the installed version.