Vulnerability Details CVE-2024-26308
Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26.
Users are recommended to upgrade to version 1.26, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.5%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2024-26308
-
cpe:2.3:a:apache:commons_compress:1.21
-
cpe:2.3:a:apache:commons_compress:1.22
-
cpe:2.3:a:apache:commons_compress:1.23.0
-
cpe:2.3:a:apache:commons_compress:1.24.0
-
cpe:2.3:a:apache:commons_compress:1.25.0