Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Commons Compress users should upgrade to 1.21 or later.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-1798 | When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package. |
Github GHSA |
GHSA-mc84-pj99-q6hh | Improper Handling of Length Parameter Inconsistency in Compress |
Thu, 08 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-10-08T21:03:29.070Z
Reserved: 2021-07-01T00:00:00.000Z
Link: CVE-2021-36090
Updated: 2024-08-04T00:47:43.813Z
Status : Modified
Published: 2021-07-13T08:15:07.310
Modified: 2026-10-08T21:17:36.683
Link: CVE-2021-36090
OpenCVE Enrichment
No data.
-
CWE-130
Improper Handling of Length Parameter Inconsistency
-
CWE-770
Allocation of Resources Without Limits or Throttling
- NVD-CWE-Other
EUVD
Github GHSA