GHSA-7hfm-57qf-j43q
GitHub Security Advisory
Excessive Iteration in Compress
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
Affected Packages
Maven
org.apache.commons:commons-compress
Affected versions:
0
(fixed in 1.21)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 27, 2025 6:35 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.