Loading HuntDB...

GHSA-7hfm-57qf-j43q

GitHub Security Advisory

Excessive Iteration in Compress

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.

Affected Packages

Maven org.apache.commons:commons-compress
Affected versions: 0 (fixed in 1.21)

Related CVEs

Key Information

GHSA ID
GHSA-7hfm-57qf-j43q
Published
August 2, 2021 4:55 PM
Last Modified
February 8, 2022 9:08 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.apache.commons:commons-compress
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.