CVE-2021-36089: Zope Grok

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Grok 7.6.6 through 9.2.0 has a heap-based buffer overflow in grk::FileFormatDecompress::apply_palette_clr (called from grk::FileFormatDecompress::applyColour).

Affected products

  • Zope Grok: from 7.6.6, up to and including 9.2.0

Published 2021-07-01. Last modified 2026-06-17.