An open index of dependabot pull requests across open source projects.

Uncontrolled Resource Consumption in Apache Commons Compress

RSS Feed MODERATE
GHSA-6fxm-66hq-fc96 CVE-2012-2098
Description:

Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.

Affected Packages
Ecosystem Package Vulnerable Versions Patched Version
maven org.apache.commons:commons-compress < 1.4.1
1.4.1
Related Dependabot Pull Requests
Advisory Details
Published: May 13, 2022 about 4 years ago
Updated: June 24, 2026 30 days ago
EPSS: 12.61% 96th percentile
Source: Github
Classification: GENERAL
UUID: GSA_kwCzR0hTQS02ZnhtLTY2aHEtZmM5Ns3tzQ
References