GHSA-9qvj-rpj8-v5c8 · Severity: medium · Ecosystem: maven — Pekko Management may not properly apply authenticator when Basic Authentication is enabled
If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to upgrade to version 1.1.1, which fixes this issue. Akka was affected by the same issue and has released the fix in version 1.6.1.
Conclusion & alert: CVE-2025-46548 is rated High Exploit Risk (70.8/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.73%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-30 | 0.77% | 1.73% | +0.96% |
| 2 | 2026-02-17 | 0.69% | 0.77% | +0.08% |
| 3 | 2025-12-28 | — | 0.69% | — |
Full EPSS history (15 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
3.9 | 2.5 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-9qvj-rpj8-v5c8 · Severity: medium · Ecosystem: maven — Pekko Management may not properly apply authenticator when Basic Authentication is enabled
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | pekko_management | >= 1.0.0, <= 1.1.1 | cpe:2.3:a:apache:pekko_management:*:*:*:*:*:*:*:* |
| akka | akka_management | < 1.6.1 | cpe:2.3:a:akka:akka_management:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/akka/akka-management/pull/1385 | Exploit Issue Tracking |
| https://github.com/apache/pekko-management/pull/418 | Issue Tracking Patch |
| https://lists.apache.org/thread/tnd84hj9w0ggjcft6cp12q67d5jzhp66 | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/06/03/7 | Mailing List Third Party Advisory |