CVE-2025-53393

MEDIUM

Akka <2.10.6 - Deserialization

Title source: llm

Description

In Akka through 2.10.6, akka-cluster-metrics uses Java serialization for cluster metrics.

Scores

CVSS v3 6.0
EPSS 0.0009
EPSS Percentile 25.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L

Classification

CWE
CWE-502
Status draft

Affected Products (2)

com.typesafe.akka/akka-cluster-metrics_3 Maven
com.typesafe.akka/akka-cluster-metrics_2.13 Maven

Timeline

Published Jun 28, 2025
Tracked Since Feb 18, 2026