{"id":"GHSA-9qgc-p27w-3hjg","summary":"High severity vulnerability that affects com.typesafe.akka:akka-http-core_2.11 and com.typesafe.akka:akka-http-core_2.12","details":"The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attackers to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.","aliases":["CVE-2018-16131"],"modified":"2023-11-01T04:49:03.947092Z","published":"2018-10-22T20:37:07Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:29:22Z","nvd_published_at":null,"cwe_ids":["CWE-400"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-16131"},{"type":"WEB","url":"https://github.com/akka/akka-http/issues/2137"},{"type":"WEB","url":"https://akka.io/blog/news/2018/08/30/akka-http-dos-vulnerability-found"},{"type":"WEB","url":"https://doc.akka.io/docs/akka-http/current/security/2018-09-05-denial-of-service-via-decodeRequest.html"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9qgc-p27w-3hjg"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/akka-security/Dj7INsYWdjg"}],"affected":[{"package":{"name":"com.typesafe.akka:akka-http-core_2.12","ecosystem":"Maven","purl":"pkg:maven/com.typesafe.akka/akka-http-core_2.12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.0"},{"fixed":"10.1.4"}]}],"versions":["10.1.0","10.1.1","10.1.2","10.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-9qgc-p27w-3hjg/GHSA-9qgc-p27w-3hjg.json"}},{"package":{"name":"com.typesafe.akka:akka-http-core_2.11","ecosystem":"Maven","purl":"pkg:maven/com.typesafe.akka/akka-http-core_2.11"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"10.1.0"},{"fixed":"10.1.4"}]}],"versions":["10.1.0","10.1.1","10.1.2","10.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-9qgc-p27w-3hjg/GHSA-9qgc-p27w-3hjg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}