GHSA-h436-432x-8fvx
GitHub Security Advisory
Apache Commons Compress vulnerable to denial of service due to infinite loop
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package.
Affected Packages
Maven
org.apache.commons:commons-compress
Affected versions:
1.11
(fixed in 1.16)
Maven
com.liferay:com.liferay.portal.tools.bundle.support
Affected versions:
3.2.7
(fixed in 3.7.4)
Maven
io.takari:commons-compress
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 28, 2025 6:37 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.