Lucene search

K
osvGoogleOSV:GHSA-53X6-4X5P-RRVV
HistoryOct 11, 2019 - 6:41 p.m.

Denial of Service in Apache Commons Compress

2019-10-1118:41:08
Google
osv.dev
22

0.005 Low

EPSS

Percentile

76.3%

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

References