
Cloud Vulnerability DB
A community-led vulnerabilities database
A critical vulnerability (CVE-2021-20236) was discovered in the ZeroMQ server versions prior to 4.3.3. The vulnerability was found in the PUB/XPUB subscription store functionality, allowing malicious clients to cause a stack buffer overflow on the server through crafted topic subscription requests followed by unsubscription (NVD, GitHub Advisory).
The vulnerability exists in the PUB/XPUB subscription store (mtrie) which uses recursive function calls for traversal. During the unsubscription process, the recursive calls are not tail calls, causing the stack to grow linearly with the subscription topic length. The vulnerability has received a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating its severe nature (NVD, GitHub Advisory).
The vulnerability poses significant threats to system confidentiality, integrity, and availability. Since topics are under the control of remote clients, attackers can send subscriptions with arbitrary length topics, leading to potential stack overflows which are more dangerous than normal OOM situations and could potentially lead to other exploits (GitHub Advisory).
The vulnerability affects users with listening TCP PUB/XPUB endpoints who do not use CURVE/ZAP for authentication. An attacker can exploit this by sending subscription requests with specially crafted topics and then unsubscribing, causing the server to create an mtrie sufficiently large to trigger a stack overflow during traversal (GitHub Advisory).
The vulnerability has been patched in ZeroMQ version 4.3.3. Users are strongly advised to upgrade to this version or later as no alternative workarounds are available (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."