Skip to main content
HIGH

CVE-2021-37137

CVSS v3

7.5

HIGH

EPSS Score

6.6 %

exploit probability, as of 2026-10-09

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published
2021-09-09
Last Modified
2026-10-08

Frequently asked questions

What is CVE-2021-37137?

The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.

Is CVE-2021-37137 actively exploited?

Active exploitation of CVE-2021-37137 has not been confirmed. Its EPSS score was 6.6% on 2026-10-09, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-37137?

CVE-2021-37137 has a CVSS v3 base score of 7.5 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.

Is CVE-2021-37137 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key