CVE-2021-35517

HIGH

Compress - Memory Corruption

Title source: llm

Description

When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.

Exploits (2)

nomisec WORKING POC
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2021-35517-commons-compress-vulnerable
nomisec WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2021-35517-commons-compress-vulnerable

References (22)

... and 2 more

Scores

CVSS v3 7.5
EPSS 0.0106
EPSS Percentile 77.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-130 CWE-770
Status published
Products (48)
apache/commons_compress 1.1 - 1.20
netapp/active_iq_unified_manager (3 CPE variants)
netapp/oncommand_insight
oracle/banking_apis 19.1
oracle/banking_apis 19.2
oracle/banking_apis 20.1
oracle/banking_apis 21.1
oracle/banking_apis 18.1 - 18.3
oracle/banking_digital_experience 19.1
oracle/banking_digital_experience 19.2
... and 38 more
Published Jul 13, 2021
Tracked Since Feb 18, 2026