Back

HIGH

Apache Commons Compress 1.0 to 1.20 denial of service vulnerability

Published Jul 13, 2021

Description

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

Affected products

Remediation

Vendor solution

Commons Compress users should upgrade to 1.21 or later.

Metrics

References (64)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jul 13, 2021
Updated Aug 4, 2024
Reserved Jul 1, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 13, 2021
GHSA-MC84-PJ99-Q6HH