{"id":"CVE-2021-37136","title":"The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression)","summary":"The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input c…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-400"],"vendor":"netty","product":"netty","affected":["netty < 4.1.68","quarkus < 2.2.4","banking_apis >= 18.1, <= 18.3","banking_apis = 19.1","banking_apis = 19.2","banking_apis = 20.1","banking_apis = 21.1","banking_digital_experience = 18.1","banking_digital_experience = 18.2","banking_digital_experience = 18.3","banking_digital_experience = 19.1","banking_digital_experience = 19.2","banking_digital_experience = 20.1","banking_digital_experience = 21.1","coherence = 12.2.1.4.0","coherence = 14.1.1.0.0","commerce_guided_search = 11.3.2","communications_brm_-_elastic_charging_engine < 12.0.0.4.6","communications_brm_-_elastic_charging_engine = 12","communications_cloud_native_core_binding_support_function = 1.10.0","communications_cloud_native_core_binding_support_function = 1.11.0","communications_cloud_native_core_network_slice_selection_function = 1.8.0","communications_cloud_native_core_policy = 1.15.0","communications_cloud_native_core_security_edge_protection_proxy = 1.7.0","communications_cloud_native_core_unified_data_repository = 1.15.0","communications_diameter_signaling_router >= 8.0.0.0, <= 8.5.0.2","communications_instant_messaging_server = 8.1","helidon = 1.4.10","helidon = 2.4.0","peoplesoft_enterprise_peopletools = 8.48","peoplesoft_enterprise_peopletools = 8.57","peoplesoft_enterprise_peopletools = 8.58","peoplesoft_enterprise_peopletools = 8.59","webcenter_portal = 12.2.1.3.0","webcenter_portal = 12.2.1.4.0","oncommand_insight","debian_linux = 10.0","debian_linux = 11.0"],"patched":["netty 4.1.68","quarkus 2.2.4","communications_brm_-_elastic_charging_engine 12.0.0.4.6"],"published":"2021-10-19","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:10.643","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-37136","references":[{"url":"https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv","label":"reefs@jfrog.com"},{"url":"https://lists.apache.org/thread.html/r06a145c9bd41a7344da242cef07977b24abe3349161ede948e30913d%40%3Ccommits.druid.apache.org%3E","label":"reefs@jfrog.com"},{"url":"https://lists.apache.org/thread.html/r5406eaf3b07577d233b9f07cfc8f26e28369e6bab5edfcab41f28abb%40%3Ccommits.druid.apache.org%3E","label":"reefs@jfrog.com"},{"url":"https://lists.apache.org/thread.html/r5e05eba32476c580412f9fbdfc9b8782d5b40558018ac4ac07192a04%40%3Ccommits.druid.apache.org%3E","label":"reefs@jfrog.com"},{"url":"https://lists.apache.org/thread.html/r75490c61c2cb7b6ae2c81238fd52ae13636c60435abcd732d41531a0%40%3Ccommits.druid.apache.org%3E","label":"reefs@jfrog.com"},{"url":"https://lists.apache.org/thread.html/rd262f59b1586a108e320e5c966feeafbb1b8cdc96965debc7cc10b16%40%3Ccommits.druid.apache.org%3E","label":"reefs@jfrog.com"},{"url":"https://lists.apache.org/thread.html/rfb2bf8597e53364ccab212fbcbb2a4e9f0a9e1429b1dc08023c6868e%40%3Cdev.tinkerpop.apache.org%3E","label":"reefs@jfrog.com"},{"url":"https://lists.debian.org/debian-lts-announce/2023/01/msg00008.html","label":"reefs@jfrog.com"},{"url":"https://security.netapp.com/advisory/ntap-20220210-0012/","label":"reefs@jfrog.com"},{"url":"https://www.debian.org/security/2023/dsa-5316","label":"reefs@jfrog.com"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"reefs@jfrog.com"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"reefs@jfrog.com"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"reefs@jfrog.com"},{"url":"https://github.com/netty/netty/security/advisories/GHSA-grg4-wf29-r9vv","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r06a145c9bd41a7344da242cef07977b24abe3349161ede948e30913d%40%3Ccommits.druid.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r5406eaf3b07577d233b9f07cfc8f26e28369e6bab5edfcab41f28abb%40%3Ccommits.druid.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r5e05eba32476c580412f9fbdfc9b8782d5b40558018ac4ac07192a04%40%3Ccommits.druid.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r75490c61c2cb7b6ae2c81238fd52ae13636c60435abcd732d41531a0%40%3Ccommits.druid.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rd262f59b1586a108e320e5c966feeafbb1b8cdc96965debc7cc10b16%40%3Ccommits.druid.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rfb2bf8597e53364ccab212fbcbb2a4e9f0a9e1429b1dc08023c6868e%40%3Cdev.tinkerpop.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/01/msg00008.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20220210-0012/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2023/dsa-5316","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.05908,"epssPercentile":0.93046,"ingestedAt":"2026-10-08T23:16:47.324Z","slug":"CVE-2021-37136","body":"## Overview\n\nThe Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack\n\n## Affected\n\n- `netty < 4.1.68`\n- `quarkus < 2.2.4`\n- `banking_apis >= 18.1, <= 18.3`\n- `banking_apis = 19.1`\n- `banking_apis = 19.2`\n- `banking_apis = 20.1`\n- `banking_apis = 21.1`\n- `banking_digital_experience = 18.1`\n- `banking_digital_experience = 18.2`\n- `banking_digital_experience = 18.3`\n- `banking_digital_experience = 19.1`\n- `banking_digital_experience = 19.2`\n- `banking_digital_experience = 20.1`\n- `banking_digital_experience = 21.1`\n- `coherence = 12.2.1.4.0`\n- `coherence = 14.1.1.0.0`\n- `commerce_guided_search = 11.3.2`\n- `communications_brm_-_elastic_charging_engine < 12.0.0.4.6`\n- `communications_brm_-_elastic_charging_engine = 12`\n- `communications_cloud_native_core_binding_support_function = 1.10.0`\n- `communications_cloud_native_core_binding_support_function = 1.11.0`\n- `communications_cloud_native_core_network_slice_selection_function = 1.8.0`\n- `communications_cloud_native_core_policy = 1.15.0`\n- `communications_cloud_native_core_security_edge_protection_proxy = 1.7.0`\n- `communications_cloud_native_core_unified_data_repository = 1.15.0`\n- `communications_diameter_signaling_router >= 8.0.0.0, <= 8.5.0.2`\n- `communications_instant_messaging_server = 8.1`\n- `helidon = 1.4.10`\n- `helidon = 2.4.0`\n- `peoplesoft_enterprise_peopletools = 8.48`\n- `peoplesoft_enterprise_peopletools = 8.57`\n- `peoplesoft_enterprise_peopletools = 8.58`\n- `peoplesoft_enterprise_peopletools = 8.59`\n- `webcenter_portal = 12.2.1.3.0`\n- `webcenter_portal = 12.2.1.4.0`\n- `oncommand_insight`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `netty 4.1.68`\n- `quarkus 2.2.4`\n- `communications_brm_-_elastic_charging_engine 12.0.0.4.6`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":1.2,"exploitation":0,"ransomware":0},"changes":[]}