CVE-2025-61778
Last modified
CVE-2025-61778 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enabled via our `akka.remote.dot-netty.tcp` transport and this would correctly enforce private key validation on the server-side of inbound connections. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enabled via our `akka.remote.dot-netty.tcp` transport and this would correctly enforce private key validation on the server-side of inbound connections. Akka.Remote, however, never asked the outbound-connecting client to present ITS certificate - therefore it's possible for untrusted parties to connect to a private key'd Akka.NET cluster and begin communicating with it without any certificate. The issue here is that for certificate-based authentication to work properly, ensuring that all members of the Akka.Remote network are secured with the same private key, Akka.Remote needed to implement mutual TLS. This was not the case before Akka.NET v1.5.52. Those who run Akka.NET inside a private network that they fully control or who were never using TLS in the first place are now affected by the bug. However, those who use TLS to secure their networks must upgrade to Akka.NET V1.5.52 or later. One patch forces "fail fast" semantics if TLS is enabled but the private key is missing or invalid. Previous versions would only check that once connection attempts occurred. The second patch, a critical fix, enforces mutual TLS (mTLS) by default, so both parties must be keyed using the same certificate. As a workaround, avoid exposing the application publicly to avoid the vulnerability having a practical impact on one's application. However, upgrading to version 1.5.52 is still recommended by the maintainers.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-61778?
How severe is CVE-2025-61778?
How do I fix CVE-2025-61778?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-61772Rack is a modular Ruby web server interface. In versions pri…7.5
- CVE-2025-61773pyLoad is a free and open-source download manager written in…8.1
- CVE-2025-61774PyVista provides 3D plotting and mesh analysis through an in…9.3
- CVE-2025-61775Vickey is a Misskey-based microblogging platform. A vulnerab…6.9
- CVE-2025-61776Dependency-Track is a component analysis platform that allow…4.7
- CVE-2025-61777Flag Forge is a Capture The Flag (CTF) platform. Starting in…9.1
- CVE-2025-61779Confidential Containers's Trustee project contains tools and…8.7
- CVE-2025-61780Rack is a modular Ruby web server interface. Prior to versio…5.3
- CVE-2025-61781OpenCTI is an open source platform for managing cyber threat…9.1
- CVE-2025-61782OpenCTI is an open source platform for managing cyber threat…6.1
- CVE-2025-61783Python Social Auth is a social authentication/registration m…6.3
- CVE-2025-61784LLaMA-Factory is a tuning library for large language models.…8.1
Are you affected by CVE-2025-61778?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
