VYPR
High severity7.5NVD Advisory· Published Nov 2, 2021· Updated Jun 17, 2026

CVE-2021-42697

CVE-2021-42697

Description

Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.typesafe.akka:akka-http-core_2.13.0-RC3Maven
>= 10.1.0
com.typesafe.akka:akka-http-core_2.13.0-RC2Maven
>= 10.1.0
com.typesafe.akka:akka-http-core_2.13.0-M5Maven
>= 10.1.0
com.typesafe.akka:aakka-http-core_2.13.0-M3Maven
>= 10.1.0
com.typesafe.akka:akka-http-core_2.13Maven
>= 10.1.0, < 10.1.1510.1.15
com.typesafe.akka:akka-http-core_2.13Maven
>= 10.2.0-M1, < 10.2.710.2.7
com.typesafe.akka:akka-http-core_2.12Maven
>= 10.1.0, < 10.1.1510.1.15
com.typesafe.akka:akka-http-core_2.12Maven
>= 10.2.0-M1, < 10.2.710.2.7
com.typesafe.akka:akka-http-core_2.11Maven
>= 10.1.0, < 10.1.1510.1.15

Affected products

9

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.