CVE Tools

Lightbend

7 CVEs tracked since 2018. Since Aug 2018, none of them reached CISA KEV.

Lightbend CVEs per month

Aug 2018 to Nov 2020. Point at a month, or focus the strip and use the arrow keys.
Lightbend CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0820
2018-09null or fewer
2018-1020
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-1130

Products

The products that kept showing up in Lightbend's monthly top three, with their CVEs summed over those months.

  1. Play Framework31 month
  2. Spray-json21 month
  3. Akka11 month
  4. Akka HTTP11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Lightbend.

  1. CVE-2025-46548Apache Pekko Management, Apache Pekko Management, Apache Pekko Management, Akka Management, Akka Management, Akka Management: management API basic authentication is not effective6.5
  2. CVE-2023-33251When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linu...4.7
  3. CVE-2023-31442In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictable DNS transaction IDs when resolving DNS records, making ...7.5
  4. CVE-2023-29471Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.inte...5.5
  5. CVE-2022-31023Dev error stack trace leaking into prod in Play Framework5.9
  6. CVE-2022-31018Denial of service binding form from JSON in Play Framework7.5
  7. CVE-2021-23339HTTP Request Smuggling5.0
  8. CVE-2020-28923An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version prio...2.7
  9. CVE-2020-26882In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.7.5
  10. CVE-2020-27196An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON structure sent to a va...7.5
  11. CVE-2020-26883In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.7.5
  12. CVE-2020-12480In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.6.5
  13. CVE-2019-17598An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when ...7.5
  14. CVE-2018-18854Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of many JSON object fields ...7.5
  15. CVE-2018-18853Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of a field composed of many...7.5

The record

Peak rank
#109 in Nov 2020
Busiest month shown
Nov 2020, 3 CVEs
Months with a KEV entry
0 since Aug 2018
Monthly snapshots
3 since 2018
Lightbend's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store