CVE-2021-36090

HIGH

Compress - Memory Corruption

Title source: llm

Description

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

Exploits (2)

nomisec STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2021-36090-commons-compress-vulnerable
nomisec WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2021-36090-commons-compress-vulnerable

References (34)

... and 14 more

Scores

CVSS v3 7.5
EPSS 0.0059
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-130
Status published
Products (48)
apache/commons_compress 1.0 - 1.21
netapp/active_iq_unified_manager (3 CPE variants)
netapp/oncommand_insight
oracle/banking_apis 19.1
oracle/banking_apis 19.2
oracle/banking_apis 20.1
oracle/banking_apis 21.1
oracle/banking_apis 18.1 - 18.3
oracle/banking_digital_experience 19.1
oracle/banking_digital_experience 19.2
... and 38 more
Published Jul 13, 2021
Tracked Since Feb 18, 2026