---
id: CVE-2021-36090
title: >-
  When reading a specially crafted ZIP archive, Compress can be made to allocate
  large amounts of memory that finally leads to an out of memory error even for
  very small inputs
summary: >-
  When reading a specially crafted ZIP archive, Compress can be made to allocate
  large amounts of memory that finally leads to an out of memory error even for
  very small inputs. This could be used to mount a denial of service attack
  agains…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-130
vendor: apache
product: commons_compress
affected:
  - 'commons_compress >= 1.0, < 1.21'
  - 'banking_apis >= 18.1, <= 18.3'
  - banking_apis = 19.1
  - banking_apis = 19.2
  - banking_apis = 20.1
  - banking_apis = 21.1
  - 'banking_digital_experience >= 18.1, <= 18.3'
  - banking_digital_experience = 19.1
  - banking_digital_experience = 19.2
  - banking_digital_experience = 20.1
  - banking_digital_experience = 21.1
  - banking_enterprise_default_management = 2.7.0
  - banking_party_management = 2.7.0
  - banking_payments = 14.5
  - banking_platform = 2.6.2
  - banking_platform = 2.7.1
  - banking_platform = 2.9.0
  - banking_platform = 2.12.0
  - banking_trade_finance = 14.5
  - banking_treasury_management = 14.5
  - business_process_management_suite = 12.2.1.3.0
  - business_process_management_suite = 12.2.1.4.0
  - commerce_guided_search = 11.3.2
  - communications_billing_and_revenue_management = 12.0.0.4
  - communications_cloud_native_core_automated_test_suite = 1.8.0
  - communications_cloud_native_core_service_communication_proxy = 1.14.0
  - communications_cloud_native_core_unified_data_repository = 1.14.0
  - 'communications_diameter_intelligence_hub >= 8.0.0, <= 8.2.3'
  - communications_diameter_intelligence_hub = 8.2.3
  - 'communications_element_manager >= 8.2.0, <= 8.2.4.0'
  - 'communications_session_report_manager >= 8.2.0, <= 8.2.5.0'
  - 'communications_session_route_manager >= 8.0.0, <= 8.2.5.0'
  - communications_unified_inventory_management = 7.4.0
  - communications_unified_inventory_management = 7.4.1
  - communications_unified_inventory_management = 7.4.2
  - communications_unified_inventory_management = 7.5.0
  - 'financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.1'
  - financial_services_crime_and_compliance_management_studio = 8.0.8.2.0
  - financial_services_crime_and_compliance_management_studio = 8.0.8.3.0
  - financial_services_enterprise_case_management
  - financial_services_enterprise_case_management = 8.0.7.2.0
  - financial_services_enterprise_case_management = 8.0.8.1.0
  - 'flexcube_universal_banking >= 14.0.0, <= 14.3.0'
  - flexcube_universal_banking = 12.4
  - flexcube_universal_banking = 14.5
  - healthcare_data_repository = 8.1.0
  - insurance_policy_administration = 11.0.2
  - insurance_policy_administration = 11.1.0
  - insurance_policy_administration = 11.2.8
  - insurance_policy_administration = 11.3.0
  - insurance_policy_administration = 11.3.1
  - peoplesoft_enterprise_peopletools = 8.57
  - peoplesoft_enterprise_peopletools = 8.58
  - peoplesoft_enterprise_peopletools = 8.59
  - 'primavera_gateway >= 17.12.0, <= 17.12.11'
  - 'primavera_gateway >= 18.8.0, <= 18.8.12'
  - 'primavera_gateway >= 19.12.0, <= 19.12.11'
  - 'primavera_gateway >= 20.12.0, <= 20.12.7'
  - 'primavera_unifier >= 17.7, <= 17.12'
  - primavera_unifier = 18.8
  - primavera_unifier = 19.12
  - primavera_unifier = 20.12
  - utilities_testing_accelerator = 6.0.0.1.1
  - utilities_testing_accelerator = 6.0.0.2.2
  - utilities_testing_accelerator = 6.0.0.3.1
  - webcenter_portal = 12.2.1.3.0
  - webcenter_portal = 12.2.1.4.0
  - communications_messaging_server = 8.1
  - active_iq_unified_manager
  - oncommand_insight
patched:
  - commons_compress 1.21
published: '2021-07-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:36.683'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-36090'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2021/07/13/4'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2021/07/13/6'
    label: security@apache.org
  - url: 'https://commons.apache.org/proper/commons-compress/security-reports.html'
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r0e87177f8e78b4ee453cd4d3d8f4ddec6f10d2c27707dd71e12cafc9%40%3Cannounce.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r25f4c44616045085bc3cf901bb7e68e445eee53d1966fc08998fc456%40%3Cdev.drill.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r3227b1287e5bd8db6523b862c22676b046ad8f4fc96433225f46a2bd%40%3Cissues.drill.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r4f03c5de923e3f2a8c316248681258125140514ef3307bfe1538e1ab%40%3Cdev.drill.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r54049b66afbca766b6763c7531e9fe7a20293a112bcb65462a134949%40%3Ccommits.drill.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r67ef3c07fe3b8c1b02d48012149d280ad6da8e4cec253b527520fb2b%40%3Cdev.poi.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r75ffc7a461e7e7ae77690fa75bd47bb71365c732e0fbcc44da4f8ff5%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r9a23d4dbf4e34d498664080bff59f2893b855eb16dae33e4aa92fa53%40%3Cannounce.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r9f54c0caa462267e0cc68b49f141e91432b36b23348d18c65bd0d040%40%3Cnotifications.skywalking.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rab292091eadd1ecc63c516e9541a7f241091cf2e652b8185a6059945%40%3Ccommits.druid.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/racd0c0381c8404f298b226cd9db2eaae965b14c9c568224aa3f437ae%40%3Cnotifications.skywalking.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rb064d705fdfa44b5dae4c366b369ef6597951083196321773b983e71%40%3Ccommits.pulsar.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rb5fa2ee61828fa2e42361b58468717e84902dd71c4aea8dc0b865df7%40%3Cnotifications.james.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rb6e1fa80d34e5ada45f72655d84bfd90db0ca44ef19236a49198c88c%40%3Cnotifications.skywalking.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rb7adf3e55359819e77230b4586521e5c6874ce5ed93384bdc14d6aee%40%3Cnotifications.skywalking.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rba65ed5ddb0586f5b12598f55ec7db3633e7b7fede60466367fbf86a%40%3Cnotifications.skywalking.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rbbf42642c3e4167788a7c13763d192ee049604d099681f765385d99d%40%3Cdev.drill.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rbe91c512c5385181149ab087b6c909825d34299f5c491c6482a2ed57%40%3Ccommits.druid.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rc4134026d7d7b053d4f9f2205531122732405012c8804fd850a9b26f%40%3Cuser.commons.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rc7df4c2f0bbe2028a1498a46d322c91184f7a369e3e4c57d9518cacf%40%3Cdev.drill.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rd4332baaf6debd03d60deb7ec93bee49e5fdbe958cb6800dff7fb00e%40%3Cnotifications.skywalking.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314d50bc1ed36e81d38%40%3Cuser.ant.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rf2f4d7940371a7c7c5b679f50e28fc7fcc82cd00670ced87e013ac88%40%3Ccommits.druid.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rf3f0a09fee197168a813966c5816157f6c600a47313a0d6813148ea6%40%3Cissues.drill.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rf93b6bb267580e01deb7f3696f7eaca00a290c66189a658cf7230a1a%40%3Cissues.drill.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rfba19167efc785ad3561e7ef29f340d65ac8f0d897aed00e0731e742%40%3Cnotifications.skywalking.apache.org%3E
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20211022-0001/'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: security@apache.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2021/07/13/4'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2021/07/13/6'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://commons.apache.org/proper/commons-compress/security-reports.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r0e87177f8e78b4ee453cd4d3d8f4ddec6f10d2c27707dd71e12cafc9%40%3Cannounce.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r25f4c44616045085bc3cf901bb7e68e445eee53d1966fc08998fc456%40%3Cdev.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r3227b1287e5bd8db6523b862c22676b046ad8f4fc96433225f46a2bd%40%3Cissues.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r4f03c5de923e3f2a8c316248681258125140514ef3307bfe1538e1ab%40%3Cdev.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r54049b66afbca766b6763c7531e9fe7a20293a112bcb65462a134949%40%3Ccommits.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r67ef3c07fe3b8c1b02d48012149d280ad6da8e4cec253b527520fb2b%40%3Cdev.poi.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r75ffc7a461e7e7ae77690fa75bd47bb71365c732e0fbcc44da4f8ff5%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r9a23d4dbf4e34d498664080bff59f2893b855eb16dae33e4aa92fa53%40%3Cannounce.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/r9f54c0caa462267e0cc68b49f141e91432b36b23348d18c65bd0d040%40%3Cnotifications.skywalking.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rab292091eadd1ecc63c516e9541a7f241091cf2e652b8185a6059945%40%3Ccommits.druid.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/racd0c0381c8404f298b226cd9db2eaae965b14c9c568224aa3f437ae%40%3Cnotifications.skywalking.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rb064d705fdfa44b5dae4c366b369ef6597951083196321773b983e71%40%3Ccommits.pulsar.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rb5fa2ee61828fa2e42361b58468717e84902dd71c4aea8dc0b865df7%40%3Cnotifications.james.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rb6e1fa80d34e5ada45f72655d84bfd90db0ca44ef19236a49198c88c%40%3Cnotifications.skywalking.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rb7adf3e55359819e77230b4586521e5c6874ce5ed93384bdc14d6aee%40%3Cnotifications.skywalking.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rba65ed5ddb0586f5b12598f55ec7db3633e7b7fede60466367fbf86a%40%3Cnotifications.skywalking.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rbbf42642c3e4167788a7c13763d192ee049604d099681f765385d99d%40%3Cdev.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rbe91c512c5385181149ab087b6c909825d34299f5c491c6482a2ed57%40%3Ccommits.druid.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc4134026d7d7b053d4f9f2205531122732405012c8804fd850a9b26f%40%3Cuser.commons.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rc7df4c2f0bbe2028a1498a46d322c91184f7a369e3e4c57d9518cacf%40%3Cdev.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rd4332baaf6debd03d60deb7ec93bee49e5fdbe958cb6800dff7fb00e%40%3Cnotifications.skywalking.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rdd5412a5b9a25aed2a02c3317052d38a97128314d50bc1ed36e81d38%40%3Cuser.ant.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf2f4d7940371a7c7c5b679f50e28fc7fcc82cd00670ced87e013ac88%40%3Ccommits.druid.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf3f0a09fee197168a813966c5816157f6c600a47313a0d6813148ea6%40%3Cissues.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rf93b6bb267580e01deb7f3696f7eaca00a290c66189a658cf7230a1a%40%3Cissues.drill.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rfba19167efc785ad3561e7ef29f340d65ac8f0d897aed00e0731e742%40%3Cnotifications.skywalking.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20211022-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.12945
epssPercentile: 0.96225
ingestedAt: '2026-10-08T22:11:53.738Z'
---

## Overview

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

## Affected

- `commons_compress >= 1.0, < 1.21`
- `banking_apis >= 18.1, <= 18.3`
- `banking_apis = 19.1`
- `banking_apis = 19.2`
- `banking_apis = 20.1`
- `banking_apis = 21.1`
- `banking_digital_experience >= 18.1, <= 18.3`
- `banking_digital_experience = 19.1`
- `banking_digital_experience = 19.2`
- `banking_digital_experience = 20.1`
- `banking_digital_experience = 21.1`
- `banking_enterprise_default_management = 2.7.0`
- `banking_party_management = 2.7.0`
- `banking_payments = 14.5`
- `banking_platform = 2.6.2`
- `banking_platform = 2.7.1`
- `banking_platform = 2.9.0`
- `banking_platform = 2.12.0`
- `banking_trade_finance = 14.5`
- `banking_treasury_management = 14.5`
- `business_process_management_suite = 12.2.1.3.0`
- `business_process_management_suite = 12.2.1.4.0`
- `commerce_guided_search = 11.3.2`
- `communications_billing_and_revenue_management = 12.0.0.4`
- `communications_cloud_native_core_automated_test_suite = 1.8.0`
- `communications_cloud_native_core_service_communication_proxy = 1.14.0`
- `communications_cloud_native_core_unified_data_repository = 1.14.0`
- `communications_diameter_intelligence_hub >= 8.0.0, <= 8.2.3`
- `communications_diameter_intelligence_hub = 8.2.3`
- `communications_element_manager >= 8.2.0, <= 8.2.4.0`
- `communications_session_report_manager >= 8.2.0, <= 8.2.5.0`
- `communications_session_route_manager >= 8.0.0, <= 8.2.5.0`
- `communications_unified_inventory_management = 7.4.0`
- `communications_unified_inventory_management = 7.4.1`
- `communications_unified_inventory_management = 7.4.2`
- `communications_unified_inventory_management = 7.5.0`
- `financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.1`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.2.0`
- `financial_services_crime_and_compliance_management_studio = 8.0.8.3.0`
- `financial_services_enterprise_case_management`
- `financial_services_enterprise_case_management = 8.0.7.2.0`
- `financial_services_enterprise_case_management = 8.0.8.1.0`
- `flexcube_universal_banking >= 14.0.0, <= 14.3.0`
- `flexcube_universal_banking = 12.4`
- `flexcube_universal_banking = 14.5`
- `healthcare_data_repository = 8.1.0`
- `insurance_policy_administration = 11.0.2`
- `insurance_policy_administration = 11.1.0`
- `insurance_policy_administration = 11.2.8`
- `insurance_policy_administration = 11.3.0`
- `insurance_policy_administration = 11.3.1`
- `peoplesoft_enterprise_peopletools = 8.57`
- `peoplesoft_enterprise_peopletools = 8.58`
- `peoplesoft_enterprise_peopletools = 8.59`
- `primavera_gateway >= 17.12.0, <= 17.12.11`
- `primavera_gateway >= 18.8.0, <= 18.8.12`
- `primavera_gateway >= 19.12.0, <= 19.12.11`
- `primavera_gateway >= 20.12.0, <= 20.12.7`
- `primavera_unifier >= 17.7, <= 17.12`
- `primavera_unifier = 18.8`
- `primavera_unifier = 19.12`
- `primavera_unifier = 20.12`
- `utilities_testing_accelerator = 6.0.0.1.1`
- `utilities_testing_accelerator = 6.0.0.2.2`
- `utilities_testing_accelerator = 6.0.0.3.1`
- `webcenter_portal = 12.2.1.3.0`
- `webcenter_portal = 12.2.1.4.0`
- `communications_messaging_server = 8.1`
- `active_iq_unified_manager`
- `oncommand_insight`

## Remediation

Upgrade past the affected range:

- `commons_compress 1.21`
