Akka Lightbend Akka

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Lightbend Akka.

By the Year

In 2026 there have been 0 vulnerabilities in Lightbend Akka. Akka did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 1 9.10

It may take a day or so for new Akka vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Lightbend Akka Security Vulnerabilities

Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error
CVE-2018-16115 9.1 - Critical - August 29, 2018

Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error. A random number generator is used in Akka Remoting for TLS (both classic and Artery Remoting). Akka allows configuration of custom random number generators. For historical reasons, Akka included the AES128CounterSecureRNG and AES256CounterSecureRNG random number generators. The implementations had a bug that caused the generated numbers to be repeated after only a few bytes. The custom RNG implementations were not configured by default but examples in the documentation showed (and therefore implicitly recommended) using the custom ones. This can be used by an attacker to compromise the communication if these random number generators are enabled in configuration. It would be possible to eavesdrop, replay, or modify the messages sent with Akka Remoting/Cluster.

PRNG

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Lightbend Akka or by Lightbend? Click the Watch button to subscribe.

Lightbend
Vendor

subscribe