GHSA-grg4-wf29-r9vv · Severity: high · Ecosystem: maven — Bzip2Decoder doesn't allow setting size restrictions for decompressed data
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
Conclusion & alert: CVE-2021-37136 is rated Moderate Risk (58.3/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.19%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-04 | 0.35% | 1.19% | +0.83% |
| 2 | 2026-03-01 | 1.19% | 0.35% | -0.83% |
| 3 | 2026-02-04 | — | 1.19% | — |
Full EPSS history (34 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-grg4-wf29-r9vv · Severity: high · Ecosystem: maven — Bzip2Decoder doesn't allow setting size restrictions for decompressed data
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2021-37136 not yet assigned priority: Debian including 1 source packages (netty), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-37136 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-37136 |
suse
|
high | CVE-2021-37136 severity important: SUSE including 243 source package names (5.0.0-beta1.2.122:netty-4.1.75-150200.4.6.2, 5.1.0.6.40:netty-4.1.75-150200.4.6.2, …), 276 product×package rows across 42 product lines (Container suse/manager/5.0/x86_64/server, Container suse/multi-linux-manager/5.1/x86_64/server, … (42 product lines)): Known Affected 231, Fixed 31, Known Not Affected 14. | https://www.suse.com/security/cve/CVE-2021-37136/ |
ubuntu
|
medium | CVE-2021-37136 medium priority: Ubuntu including 1 source packages (netty), 15 status rows across 15 suites (bionic, focal, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): released 10, ignored 5. | https://ubuntu.com/security/CVE-2021-37136 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| netty | netty | < 4.1.68 | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* |
| quarkus | quarkus | < 2.2.4 | cpe:2.3:a:quarkus:quarkus:*:*:*:*:*:*:*:* |
| oracle | banking_apis | >= 18.1, <= 18.3 | cpe:2.3:a:oracle:banking_apis:*:*:*:*:*:*:*:* |
| oracle | banking_apis | 19.1 | cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:* |
| oracle | banking_apis | 19.2 | cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:* |
| oracle | banking_apis | 20.1 | cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:* |
| oracle | banking_apis | 21.1 | cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 18.1 | cpe:2.3:a:oracle:banking_digital_experience:18.1:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 18.2 | cpe:2.3:a:oracle:banking_digital_experience:18.2:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 18.3 | cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 19.1 | cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 19.2 | cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 20.1 | cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 21.1 | cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:* |
| oracle | coherence | 12.2.1.4.0 | cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | coherence | 14.1.1.0.0 | cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:* |
| oracle | commerce_guided_search | 11.3.2 | cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:* |
| oracle | communications_brm_-_elastic_charging_engine | < 12.0.0.4.6 | cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:*:*:*:*:*:*:*:* |
| oracle | communications_brm_-_elastic_charging_engine | 12 | cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12:0.0.5.0:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_binding_support_function | 1.10.0 | cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.10.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_binding_support_function | 1.11.0 | cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.11.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_network_slice_selection_function | 1.8.0 | cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_policy | 1.15.0 | cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | 1.7.0 | cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:* |
| oracle | communications_cloud_native_core_unified_data_repository | 1.15.0 | cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:* |
| oracle | communications_diameter_signaling_router | >= 8.0.0.0, <= 8.5.0.2 | cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:* |
| oracle | communications_instant_messaging_server | 8.1 | cpe:2.3:a:oracle:communications_instant_messaging_server:8.1:*:*:*:*:*:*:* |
| oracle | helidon | 1.4.10 | cpe:2.3:a:oracle:helidon:1.4.10:*:*:*:*:*:*:* |
| oracle | helidon | 2.4.0 | cpe:2.3:a:oracle:helidon:2.4.0:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.48 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.57 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.58 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* |
| oracle | peoplesoft_enterprise_peopletools | 8.59 | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:* |
| oracle | webcenter_portal | 12.2.1.3.0 | cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | webcenter_portal | 12.2.1.4.0 | cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:* |
| netapp | oncommand_insight | — | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| debian | debian_linux | 11.0 | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |