{"id":"CVE-2021-42697","aliases":["GHSA-3hw2-h67c-wq66"],"url":"https://o3.security/vulnerability/CVE-2021-42697","summary":"Uncontrolled Recursion in Akka HTTP","details":"Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.","published":"2021-11-02T22:15:08.957Z","modified":"2026-07-09T06:34:59.669080Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Maven","name":"com.typesafe.akka:akka-http-core_2.13.0-RC3","fixedVersion":null},{"ecosystem":"Maven","name":"com.typesafe.akka:akka-http-core_2.13.0-RC2","fixedVersion":null},{"ecosystem":"Maven","name":"com.typesafe.akka:akka-http-core_2.13.0-M5","fixedVersion":null},{"ecosystem":"Maven","name":"com.typesafe.akka:aakka-http-core_2.13.0-M3","fixedVersion":null},{"ecosystem":"Maven","name":"com.typesafe.akka:akka-http-core_2.13","fixedVersion":"10.1.15"},{"ecosystem":"Maven","name":"com.typesafe.akka:akka-http-core_2.13","fixedVersion":"10.2.7"},{"ecosystem":"Maven","name":"com.typesafe.akka:akka-http-core_2.12","fixedVersion":"10.1.15"},{"ecosystem":"Maven","name":"com.typesafe.akka:akka-http-core_2.12","fixedVersion":"10.2.7"},{"ecosystem":"Maven","name":"com.typesafe.akka:akka-http-core_2.11","fixedVersion":"10.1.15"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://akka.io/blog/"},{"type":"ADVISORY","url":"https://akka.io/blog/news/2021/11/02/akka-http-10.2.7-released"},{"type":"ADVISORY","url":"https://akka.io/blog/news/2021/11/22/akka-http-10.1.15-released"},{"type":"ADVISORY","url":"https://doc.akka.io/docs/akka-http/current/security/2021-CVE-2021-42697-stack-overflow-parsing-user-agent.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/167018/Akka-HTTP-10.1.14-Denial-Of-Service.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T06:34:59.669080Z"}}