PT-2025-27331 · Akka · Akka

Published

2025-06-28

·

Updated

2025-06-29

·

CVE-2025-53393

CVSS v3.1

6.0

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Akka versions through 2.10.6
Description: The issue concerns the use of Java serialization for cluster metrics in the akka-cluster-metrics component.
Recommendations: For versions through 2.10.6, consider disabling Java serialization for cluster metrics as a temporary workaround until a patch is available. Restrict access to the akka-cluster-metrics component to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2026-00090
CVE-2025-53393
GHSA-358M-FQ53-HP87

Affected Products

Akka