CLEANSTART-2025-KO30612

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2025/CLEANSTART-2025-KO30612.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2025-KO30612
Upstream
Published
2026-09-30T19:06:18Z
Modified
2026-10-01T01:00:04Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs
Details

Security vulnerability affects the apache-ant package. When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs.

References

Affected packages

CleanStart / apache-ant

Package

Name
apache-ant

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.10.11-r0

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2025/CLEANSTART-2025-KO30612.json"