CVE-2021-36374Medium· 5.5▾ SunlitWhen reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.6%
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
ant >= 1.9.0, < 1.9.16ant >= 1.10.0, < 1.10.11agile_engineering_data_management = 6.2.1.0agile_product_lifecycle_management = 9.3.6banking_trade_finance = 14.5banking_treasury_management = 14.5communications_cloud_native_core_automated_test_suite = 1.9.0communications_cloud_native_core_binding_support_function = 1.11.0communications_diameter_intelligence_hub >= 8.0.0, <= 8.1.0communications_diameter_intelligence_hub >= 8.2.0, <= 8.2.3communications_order_and_service_management = 7.3communications_order_and_service_management = 7.4communications_unified_inventory_management = 7.3.0communications_unified_inventory_management = 7.4.0communications_unified_inventory_management = 7.4.1communications_unified_inventory_management = 7.4.2communications_unified_inventory_management = 7.5.0enterprise_repository = 11.1.1.7.0financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.1.1health_sciences_information_manager >= 3.0.1, <= 3.0.5health_sciences_information_manager = 3.0.0.1insurance_policy_administration >= 11.0, <= 11.3.1primavera_gateway >= 17.12.0, <= 17.12.11primavera_gateway >= 18.8.0, <= 18.8.12primavera_gateway >= 19.12.0, <= 19.12.11primavera_gateway >= 20.12.0, <= 20.12.7primavera_unifier >= 17.7, <= 17.12primavera_unifier = 18.8primavera_unifier = 19.12primavera_unifier = 20.12product_lifecycle_analytics = 3.6.1real-time_decision_server = 3.2.0.0real-time_decision_server = 11.1.1.9.0retail_advanced_inventory_planning = 14.1retail_advanced_inventory_planning = 15.0retail_advanced_inventory_planning = 16.0retail_back_office = 14.0retail_back_office = 14.1retail_bulk_data_integration = 16.0.3.0retail_bulk_data_integration = 19.0.1retail_central_office = 14.0retail_central_office = 14.1retail_eftlink = 19.0.1retail_eftlink = 20.0.1retail_extract_transform_and_load = 13.2.8retail_financial_integration = 14.1.3.2retail_financial_integration = 15.0.4.0retail_financial_integration = 16.0.3.0retail_integration_bus = 14.1.3.2retail_integration_bus = 15.0.4.0retail_integration_bus = 16.0.3.0retail_integration_bus = 19.0.1.0retail_invoice_matching = 16.0.3retail_merchandising_system = 19.0.1retail_point-of-service = 14.0retail_point-of-service = 14.1retail_predictive_application_server = 14.1.3retail_predictive_application_server = 15.0.3retail_predictive_application_server = 16.0.3.0retail_service_backbone = 14.1.3.2retail_service_backbone = 15.0.4.0retail_service_backbone = 16.0.3.0retail_service_backbone = 19.0.1.0retail_store_inventory_management = 14.1retail_store_inventory_management = 15.0retail_store_inventory_management = 16.0retail_xstore_point_of_service = 16.0.6retail_xstore_point_of_service = 17.0.4retail_xstore_point_of_service = 18.0.3retail_xstore_point_of_service = 19.0.2retail_xstore_point_of_service = 20.0.1timesten_in-memory_database < 11.2.2.8.27utilities_framework >= 4.3.0.1.0, <= 4.3.0.6.0utilities_framework = 4.2.0.2.0utilities_framework = 4.2.0.3.0utilities_framework = 4.4.0.0.0utilities_framework = 4.4.0.2.0utilities_framework = 4.4.0.3.0utilities_testing_accelerator = 6.0.0.1.1Upgrade past the affected range:
ant 1.10.11timesten_in-memory_database 11.2.2.8.27Connected by shared product, vendor, weakness, or advisory.
CVE-2021-36373Medium· 5.5When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs
CVE-2026-78254High· 7.4The ftp and scp tasks of Apache Ant can download files from a remote server
CVE-2026-5367High· 8.6A flaw was found in OVN (Open Virtual Network)
CVE-2026-68569High· 8.1Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g
CVE-2026-87976High· 8.1Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests
CVE-2026-86089High· 7.1Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests