CVE-2017-1000118 describes a denial-of-service vulnerability in Akka HTTP versions 10.0.5 and earlier, where a specially crafted illegal media range in an Accept header can trigger a StackOverflowError. This vulnerability has a CVSS v3.0 score of 7.5 (High), indicating that an unauthenticated attacker can remotely cause a complete loss of availability with low attack complexity. While there is no evidence of active exploitation, public exploit code, or significant community discussion, its potential impact on service availability warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0.5CPE matchmatch criteria | cpe:2.3:a:akka:http_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2017-1000118
Sep 8, 2020Improper Restriction of Operations within the Bounds of a Memory Buffer in akka-http-core
Oct 22, 2018Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service
Oct 10, 2017