Apache Commons Compress < 1.26.0 - Resource Allocation Without Limits
Title source: ruleDescription
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to upgrade to version 1.26, which fixes the issue.
Exploits (1)
Scores
CVSS v3
5.5
EPSS
0.0039
EPSS Percentile
60.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Lab Environment
Details
CWE
CWE-770
Status
published
Products (2)
apache/commons_compress
1.21 - 1.26.0
org.apache.commons/commons-compress
1.21 - 1.26.0Maven
Published
Feb 19, 2024
Tracked Since
Feb 18, 2026