← Vulnerability feed

Vulnerability record · CVE-2021-20237 · published 28 May 2021

CVE-2021-20237: Zeromq libzmq uncontrolled resource consumption vulnerability

Zeromq · Libzmq

An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauthenticated attacker to send crafted PUB messages that consume excessive memory if the CURVE/ZAP authentication is disabled on the server, causing a denial of service. The highest threat from this vulnerability is to system availability.

7.5 CVSS 3.1 High EPSS 1.7% · top 23.8% CWE-400 · Uncontrolled resource consumptionCWE-401 · Memory leak
7.5CVSS 3.1 base score, v2 4.3
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. This flaw allows a remote unauthenticated attacker to send crafted PUB messages that consume excessive memory if the CURVE/ZAP authentication is disabled on the server, causing a denial of service. The highest threat from this vulnerability is to system availability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20237 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-36400Zeromq libzmq out-of-bounds write vulnerabilityZeroMQ libzmq 4.3.3 has a heap-based buffer overflow in zmq::tcp_read, a different vulnerability than CVE-2021-20235.EPSS 1.8%9.8CVE-2019-13132Zeromq libzmq out-of-bounds write vulnerabilityIn ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, runni…EPSS 42%8.8CVE-2019-6250Zeromq libzmq integer overflow vulnerabilityA pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::…EPSS 9.4%8.1CVE-2021-20235Zeromq libzmq classic buffer overflow vulnerabilityThere's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator could have its sized changed…EPSS 44%7.5CVE-2020-15166Zeromq libzmq uncontrolled resource consumption vulnerabilityIn ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, a…EPSS 3.4%6.5CVE-2021-20234Zeromq libzmq uncontrolled resource consumption vulnerabilityAn uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/pipe.cpp. This issue causes a …EPSS 1.1%7.5CVE-2026-28318SolarWinds Serv-U unauthenticated POST request denial of serviceSolarWinds Serv-U crashes when it receives a specially crafted POST request using Content-Encoding: deflate, and the crash occurs without authenticat…KEVEPSS 1.9%analysed7.5CVE-2026-45498Microsoft Defender antimalware platform uncontrolled resource consumption DoSCVE-2026-45498 is a denial of service flaw in the Microsoft Defender antimalware platform, classified as uncontrolled resource consumption (CWE-400).…KEVEPSS 1.3%analysed

Source: NIST National Vulnerability Database (record CVE-2021-20237), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.