{"id":"CVE-2021-36374","title":"When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs","summary":"When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-130"],"vendor":"apache","product":"ant","affected":["ant >= 1.9.0, < 1.9.16","ant >= 1.10.0, < 1.10.11","agile_engineering_data_management = 6.2.1.0","agile_product_lifecycle_management = 9.3.6","banking_trade_finance = 14.5","banking_treasury_management = 14.5","communications_cloud_native_core_automated_test_suite = 1.9.0","communications_cloud_native_core_binding_support_function = 1.11.0","communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0","communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3","communications_order_and_service_management = 7.3","communications_order_and_service_management = 7.4","communications_unified_inventory_management = 7.3.0","communications_unified_inventory_management = 7.4.0","communications_unified_inventory_management = 7.4.1","communications_unified_inventory_management = 7.4.2","communications_unified_inventory_management = 7.5.0","enterprise_repository = 11.1.1.7.0","financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.1","health_sciences_information_manager >= 3.0.1, <= 3.0.5","health_sciences_information_manager = 3.0.0.1","insurance_policy_administration >= 11.0, <= 11.3.1","primavera_gateway >= 17.12.0, <= 17.12.11","primavera_gateway >= 18.8.0, <= 18.8.12","primavera_gateway >= 19.12.0, <= 19.12.11","primavera_gateway >= 20.12.0, <= 20.12.7","primavera_unifier >= 17.7, <= 17.12","primavera_unifier = 18.8","primavera_unifier = 19.12","primavera_unifier = 20.12","product_lifecycle_analytics = 3.6.1","real-time_decision_server = 3.2.0.0","real-time_decision_server = 11.1.1.9.0","retail_advanced_inventory_planning = 14.1","retail_advanced_inventory_planning = 15.0","retail_advanced_inventory_planning = 16.0","retail_back_office = 14.0","retail_back_office = 14.1","retail_bulk_data_integration = 16.0.3.0","retail_bulk_data_integration = 19.0.1","retail_central_office = 14.0","retail_central_office = 14.1","retail_eftlink = 19.0.1","retail_eftlink = 20.0.1","retail_extract_transform_and_load = 13.2.8","retail_financial_integration = 14.1.3.2","retail_financial_integration = 15.0.4.0","retail_financial_integration = 16.0.3.0","retail_integration_bus = 14.1.3.2","retail_integration_bus = 15.0.4.0","retail_integration_bus = 16.0.3.0","retail_integration_bus = 19.0.1.0","retail_invoice_matching = 16.0.3","retail_merchandising_system = 19.0.1","retail_point-of-service = 14.0","retail_point-of-service = 14.1","retail_predictive_application_server = 14.1.3","retail_predictive_application_server = 15.0.3","retail_predictive_application_server = 16.0.3.0","retail_service_backbone = 14.1.3.2","retail_service_backbone = 15.0.4.0","retail_service_backbone = 16.0.3.0","retail_service_backbone = 19.0.1.0","retail_store_inventory_management = 14.1","retail_store_inventory_management = 15.0","retail_store_inventory_management = 16.0","retail_xstore_point_of_service = 16.0.6","retail_xstore_point_of_service = 17.0.4","retail_xstore_point_of_service = 18.0.3","retail_xstore_point_of_service = 19.0.2","retail_xstore_point_of_service = 20.0.1","timesten_in-memory_database < 11.2.2.8.27","utilities_framework >= 4.3.0.1.0, <= 4.3.0.6.0","utilities_framework = 4.2.0.2.0","utilities_framework = 4.2.0.3.0","utilities_framework = 4.4.0.0.0","utilities_framework = 4.4.0.2.0","utilities_framework = 4.4.0.3.0","utilities_testing_accelerator = 6.0.0.1.1"],"patched":["ant 1.10.11","timesten_in-memory_database 11.2.2.8.27"],"published":"2021-07-14","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-36374","references":[{"url":"https://ant.apache.org/security.html","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r27919fd4db07c487239c1d9771f480d89ce5ee2750aa9447309b709a%40%3Ccommits.groovy.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r544c9e8487431768465b8b2d13982c75123109bd816acf839d46010d%40%3Ccommits.groovy.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rad36f470647c5a7c02dd78c9973356d2840766d132b597b6444e373a%40%3Cnotifications.groovy.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314d50bc1ed36e81d38%40%3Cuser.ant.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rf4bb79751a02889623195715925e4fd8932dd3c97e0ade91395a96c6%40%3Cdev.myfaces.apache.org%3E","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20210819-0007/","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"security@apache.org"},{"url":"https://ant.apache.org/security.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r27919fd4db07c487239c1d9771f480d89ce5ee2750aa9447309b709a%40%3Ccommits.groovy.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r544c9e8487431768465b8b2d13982c75123109bd816acf839d46010d%40%3Ccommits.groovy.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rad36f470647c5a7c02dd78c9973356d2840766d132b597b6444e373a%40%3Cnotifications.groovy.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314d50bc1ed36e81d38%40%3Cuser.ant.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rf4bb79751a02889623195715925e4fd8932dd3c97e0ade91395a96c6%40%3Cdev.myfaces.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210819-0007/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.02642,"epssPercentile":0.84859,"ingestedAt":"2026-08-25T17:29:31.359Z","slug":"CVE-2021-36374","body":"## Overview\n\nWhen reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.\n\n## Affected\n\n- `ant >= 1.9.0, < 1.9.16`\n- `ant >= 1.10.0, < 1.10.11`\n- `agile_engineering_data_management = 6.2.1.0`\n- `agile_product_lifecycle_management = 9.3.6`\n- `banking_trade_finance = 14.5`\n- `banking_treasury_management = 14.5`\n- `communications_cloud_native_core_automated_test_suite = 1.9.0`\n- `communications_cloud_native_core_binding_support_function = 1.11.0`\n- `communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0`\n- `communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3`\n- `communications_order_and_service_management = 7.3`\n- `communications_order_and_service_management = 7.4`\n- `communications_unified_inventory_management = 7.3.0`\n- `communications_unified_inventory_management = 7.4.0`\n- `communications_unified_inventory_management = 7.4.1`\n- `communications_unified_inventory_management = 7.4.2`\n- `communications_unified_inventory_management = 7.5.0`\n- `enterprise_repository = 11.1.1.7.0`\n- `financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.1`\n- `health_sciences_information_manager >= 3.0.1, <= 3.0.5`\n- `health_sciences_information_manager = 3.0.0.1`\n- `insurance_policy_administration >= 11.0, <= 11.3.1`\n- `primavera_gateway >= 17.12.0, <= 17.12.11`\n- `primavera_gateway >= 18.8.0, <= 18.8.12`\n- `primavera_gateway >= 19.12.0, <= 19.12.11`\n- `primavera_gateway >= 20.12.0, <= 20.12.7`\n- `primavera_unifier >= 17.7, <= 17.12`\n- `primavera_unifier = 18.8`\n- `primavera_unifier = 19.12`\n- `primavera_unifier = 20.12`\n- `product_lifecycle_analytics = 3.6.1`\n- `real-time_decision_server = 3.2.0.0`\n- `real-time_decision_server = 11.1.1.9.0`\n- `retail_advanced_inventory_planning = 14.1`\n- `retail_advanced_inventory_planning = 15.0`\n- `retail_advanced_inventory_planning = 16.0`\n- `retail_back_office = 14.0`\n- `retail_back_office = 14.1`\n- `retail_bulk_data_integration = 16.0.3.0`\n- `retail_bulk_data_integration = 19.0.1`\n- `retail_central_office = 14.0`\n- `retail_central_office = 14.1`\n- `retail_eftlink = 19.0.1`\n- `retail_eftlink = 20.0.1`\n- `retail_extract_transform_and_load = 13.2.8`\n- `retail_financial_integration = 14.1.3.2`\n- `retail_financial_integration = 15.0.4.0`\n- `retail_financial_integration = 16.0.3.0`\n- `retail_integration_bus = 14.1.3.2`\n- `retail_integration_bus = 15.0.4.0`\n- `retail_integration_bus = 16.0.3.0`\n- `retail_integration_bus = 19.0.1.0`\n- `retail_invoice_matching = 16.0.3`\n- `retail_merchandising_system = 19.0.1`\n- `retail_point-of-service = 14.0`\n- `retail_point-of-service = 14.1`\n- `retail_predictive_application_server = 14.1.3`\n- `retail_predictive_application_server = 15.0.3`\n- `retail_predictive_application_server = 16.0.3.0`\n- `retail_service_backbone = 14.1.3.2`\n- `retail_service_backbone = 15.0.4.0`\n- `retail_service_backbone = 16.0.3.0`\n- `retail_service_backbone = 19.0.1.0`\n- `retail_store_inventory_management = 14.1`\n- `retail_store_inventory_management = 15.0`\n- `retail_store_inventory_management = 16.0`\n- `retail_xstore_point_of_service = 16.0.6`\n- `retail_xstore_point_of_service = 17.0.4`\n- `retail_xstore_point_of_service = 18.0.3`\n- `retail_xstore_point_of_service = 19.0.2`\n- `retail_xstore_point_of_service = 20.0.1`\n- `timesten_in-memory_database < 11.2.2.8.27`\n- `utilities_framework >= 4.3.0.1.0, <= 4.3.0.6.0`\n- `utilities_framework = 4.2.0.2.0`\n- `utilities_framework = 4.2.0.3.0`\n- `utilities_framework = 4.4.0.0.0`\n- `utilities_framework = 4.4.0.2.0`\n- `utilities_framework = 4.4.0.3.0`\n- `utilities_testing_accelerator = 6.0.0.1.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ant 1.10.11`\n- `timesten_in-memory_database 11.2.2.8.27`","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.3,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}