CVE-2021-36090High· 7.5▾ TwilightWhen reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack agains…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 2.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
13%
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
commons_compress >= 1.0, < 1.21banking_apis >= 18.1, <= 18.3banking_apis = 19.1banking_apis = 19.2banking_apis = 20.1banking_apis = 21.1banking_digital_experience >= 18.1, <= 18.3banking_digital_experience = 19.1banking_digital_experience = 19.2banking_digital_experience = 20.1banking_digital_experience = 21.1banking_enterprise_default_management = 2.7.0banking_party_management = 2.7.0banking_payments = 14.5banking_platform = 2.6.2banking_platform = 2.7.1banking_platform = 2.9.0banking_platform = 2.12.0banking_trade_finance = 14.5banking_treasury_management = 14.5business_process_management_suite = 12.2.1.3.0business_process_management_suite = 12.2.1.4.0commerce_guided_search = 11.3.2communications_billing_and_revenue_management = 12.0.0.4communications_cloud_native_core_automated_test_suite = 1.8.0communications_cloud_native_core_service_communication_proxy = 1.14.0communications_cloud_native_core_unified_data_repository = 1.14.0communications_diameter_intelligence_hub >= 8.0.0, <= 8.2.3communications_diameter_intelligence_hub = 8.2.3communications_element_manager >= 8.2.0, <= 8.2.4.0communications_session_report_manager >= 8.2.0, <= 8.2.5.0communications_session_route_manager >= 8.0.0, <= 8.2.5.0communications_unified_inventory_management = 7.4.0communications_unified_inventory_management = 7.4.1communications_unified_inventory_management = 7.4.2communications_unified_inventory_management = 7.5.0financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.1financial_services_crime_and_compliance_management_studio = 8.0.8.2.0financial_services_crime_and_compliance_management_studio = 8.0.8.3.0financial_services_enterprise_case_managementfinancial_services_enterprise_case_management = 8.0.7.2.0financial_services_enterprise_case_management = 8.0.8.1.0flexcube_universal_banking >= 14.0.0, <= 14.3.0flexcube_universal_banking = 12.4flexcube_universal_banking = 14.5healthcare_data_repository = 8.1.0insurance_policy_administration = 11.0.2insurance_policy_administration = 11.1.0insurance_policy_administration = 11.2.8insurance_policy_administration = 11.3.0insurance_policy_administration = 11.3.1peoplesoft_enterprise_peopletools = 8.57peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_peopletools = 8.59primavera_gateway >= 17.12.0, <= 17.12.11primavera_gateway >= 18.8.0, <= 18.8.12primavera_gateway >= 19.12.0, <= 19.12.11primavera_gateway >= 20.12.0, <= 20.12.7primavera_unifier >= 17.7, <= 17.12primavera_unifier = 18.8primavera_unifier = 19.12primavera_unifier = 20.12utilities_testing_accelerator = 6.0.0.1.1utilities_testing_accelerator = 6.0.0.2.2utilities_testing_accelerator = 6.0.0.3.1webcenter_portal = 12.2.1.3.0webcenter_portal = 12.2.1.4.0communications_messaging_server = 8.1active_iq_unified_manageroncommand_insightUpgrade past the affected range:
commons_compress 1.21Connected by shared product, vendor, weakness, or advisory.
CVE-2021-35517High· 7.5When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs
CVE-2021-36374Medium· 5.5When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs
CVE-2021-36373Medium· 5.5When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs
CVE-2026-5367High· 8.6A flaw was found in OVN (Open Virtual Network)
CVE-2026-104714High· 8.8Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts
CVE-2026-104713Medium· 6.5Allocation of resources without limits or throttling vulnerability in the Apache Struts REST plugin