GHSA-4g9r-vxhx-9pgx
GitHub Security Advisory
Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress. This issue affects Apache Commons Compress: from 1.3 through 1.25.0.
Users are recommended to upgrade to version 1.26.0 which fixes the issue.
Affected Packages
Maven
org.apache.commons:commons-compress
Affected versions:
1.3
(fixed in 1.26.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.