AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-36090

HIGH · CVSS 7.5 EPSS 12.95%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-07-13 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. Its EPSS score suggests a 12.9% probability of exploitation in the next 30 days. It may lead to a denial-of-service condition.

CVE
CVE-2021-36090
Severity
HIGH
CVSS
7.5
EPSS
12.95%

Original NVD Description

When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.

Related CVEs

Other vulnerabilities affecting the same vendor(s)