CVE-2021-35516

HIGH

Compress - Memory Corruption

Title source: llm

Description

When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.

Exploits (2)

nomisec STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2021-35516-commons-compress-vulnerable
nomisec WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2021-35516-commons-compress-vulnerable

References (18)

Scores

CVSS v3 7.5
EPSS 0.0140
EPSS Percentile 80.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-130 CWE-770
Status published
Products (46)
apache/commons_compress 1.6 - 1.20
netapp/active_iq_unified_manager (3 CPE variants)
netapp/oncommand_insight
oracle/banking_digital_experience 19.1
oracle/banking_digital_experience 19.2
oracle/banking_digital_experience 20.1
oracle/banking_digital_experience 21.1
oracle/banking_digital_experience 18.1 - 18.3
oracle/banking_enterprise_default_management 2.7.0
oracle/banking_party_management 2.7.0
... and 36 more
Published Jul 13, 2021
Tracked Since Feb 18, 2026