Apache Software Foundation Apache Commons Compress vulnerabilities
11 known vulnerabilities affecting apache_software_foundation/apache_commons_compress.
Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2024-26308MEDIUMCVSS 5.5≥ 1.21, < 1.26.02024-02-19
CVE-2024-26308 [MEDIUM] CWE-770 CVE-2024-26308: Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This i
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26.
Users are recommended to upgrade to version 1.26, which fixes the issue.
cvelistv5nvd
CVE-2024-25710MEDIUMCVSS 5.5≥ 1.3, ≤ 1.25.02024-02-19
CVE-2024-25710 [HIGH] CWE-835 CVE-2024-25710: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0.
Users are recommended to upgrade to version 1.26.0 which fixes the issue.
cvelistv5nvd
CVE-2023-42503MEDIUMCVSS 5.0≥ 1.22, < 1.24.02023-09-14
CVE-2023-42503 [MEDIUM] CWE-20 Apache Commons Compress: Denial of service via CPU consumption for malformed TAR file
Apache Commons Compress: Denial of service via CPU consumption for malformed TAR file
Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0.
Users are recommended to upgrade to version 1.24.0, which fixes the issue.
A third party can create a malfor
cvelistv5
CVE-2021-35515HIGHCVSS 7.5≥ 1.6, < Apache Commons Compress*2021-07-13
CVE-2021-35515 [HIGH] CWE-834 CVE-2021-35515: When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
cvelistv5nvd
CVE-2021-35516HIGHCVSS 7.5≥ 1.6, < Apache Commons Compress*2021-07-13
CVE-2021-35516 [HIGH] CWE-130 CVE-2021-35516: When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memor
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
cvelistv5nvd
CVE-2021-36090HIGHCVSS 7.5≥ Apache Commons Compress, ≤ 1.202021-07-13
CVE-2021-36090 [HIGH] CWE-130 CVE-2021-36090: When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memo
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
cvelistv5nvd
CVE-2021-35517HIGHCVSS 7.5≥ 1.1, < Apache Commons Compress*2021-07-13
CVE-2021-35517 [HIGH] CWE-130 CVE-2021-35517: When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memo
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
cvelistv5nvd
CVE-2019-12402HIGHCVSS 7.5v1.15 to 1.182019-08-30
CVE-2019-12402 [HIGH] CWE-835 CVE-2019-12402: The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get int
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
cvelistv5nvd
CVE-2018-11771MEDIUMCVSS 5.5v1.7 to 1.172018-08-16
CVE-2018-11771 [MEDIUM] CWE-835 CVE-2018-11771: When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17
When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service att
cvelistv5nvd
CVE-2018-1324MEDIUMCVSS 5.5v1.11 to 1.152018-03-16
CVE-2018-1324 [MEDIUM] CWE-835 CVE-2018-1324: A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compr
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
cvelistv5nvd
CVE-2012-2098MEDIUMCVSS 5.0≥ 1.22, < 1.24.02012-06-29
CVE-2012-2098 [MEDIUM] CWE-310 CVE-2012-2098: Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2Com
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
nvd