CVE-2012-2098: Apache Commons Compress
Medium severity, CVSS 5.0. EPSS: 12.8% chance of exploitation in the next 30 days.
Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.
Affected products
- Apache Commons Compress: before 1.4.1 (fixed in 1.4.1)
Published 2012-06-29. Last modified 2026-06-16.