CVE-2021-36089: Zope Grok
High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.
Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour).
Affected products
- Zope Grok: from 7.6.6, up to and including 9.2.0
Published 2021-07-01. Last modified 2026-06-17.