AUGUST 5, 2026
Live Feed
Back to database
Case File

CVE-2019-12402

HIGH · CVSS 7.5 EPSS 16.16%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-08-30 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects Apache. Its EPSS score suggests a 16.2% probability of exploitation in the next 30 days. It may lead to a denial-of-service condition.

CVE
CVE-2019-12402
Severity
HIGH
CVSS
7.5
EPSS
16.16%
Apache

Original NVD Description

The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.

Related CVEs

Other vulnerabilities affecting the same vendor(s)