CVE-2021-37136High· 7.5▾ TwilightThe Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input c…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 1.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
5.9%
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
netty < 4.1.68quarkus < 2.2.4banking_apis >= 18.1, <= 18.3banking_apis = 19.1banking_apis = 19.2banking_apis = 20.1banking_apis = 21.1banking_digital_experience = 18.1banking_digital_experience = 18.2banking_digital_experience = 18.3banking_digital_experience = 19.1banking_digital_experience = 19.2banking_digital_experience = 20.1banking_digital_experience = 21.1coherence = 12.2.1.4.0coherence = 14.1.1.0.0commerce_guided_search = 11.3.2communications_brm_-_elastic_charging_engine < 12.0.0.4.6communications_brm_-_elastic_charging_engine = 12communications_cloud_native_core_binding_support_function = 1.10.0communications_cloud_native_core_binding_support_function = 1.11.0communications_cloud_native_core_network_slice_selection_function = 1.8.0communications_cloud_native_core_policy = 1.15.0communications_cloud_native_core_security_edge_protection_proxy = 1.7.0communications_cloud_native_core_unified_data_repository = 1.15.0communications_diameter_signaling_router >= 8.0.0.0, <= 8.5.0.2communications_instant_messaging_server = 8.1helidon = 1.4.10helidon = 2.4.0peoplesoft_enterprise_peopletools = 8.48peoplesoft_enterprise_peopletools = 8.57peoplesoft_enterprise_peopletools = 8.58peoplesoft_enterprise_peopletools = 8.59webcenter_portal = 12.2.1.3.0webcenter_portal = 12.2.1.4.0oncommand_insightdebian_linux = 10.0debian_linux = 11.0Upgrade past the affected range:
netty 4.1.68quarkus 2.2.4communications_brm_-_elastic_charging_engine 12.0.0.4.6Connected by shared product, vendor, weakness, or advisory.
CVE-2021-37137High· 7.5The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage
CVE-2021-43797Medium· 6.5Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients
CVE-2021-21409Medium· 5.9Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients
CVE-2021-21295Medium· 5.9Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients
CVE-2021-21290Medium· 6.2Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients
CVE-2026-100661High· 7.5Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service vulnerability in the QPACK prefixed-integer decoder (QpackUtil.decodePrefixedInteger), which does not bound the numbe…