GHSA-4265-ccf5-phj5
GitHub Security Advisory
Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress. This issue affects Apache Commons Compress: from 1.21 before 1.26.
Users are recommended to upgrade to version 1.26, which fixes the issue.
Affected Packages
Maven
org.apache.commons:commons-compress
Affected versions:
1.21
(fixed in 1.26.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.