CVE-2021-37137
CVSS v3
7.5
HIGH
EPSS Score
6.6 %
exploit probability, as of 2026-10-09
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
Technical details
- CVSS v3 Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Published
- 2021-09-09
- Last Modified
- 2026-10-08
Frequently asked questions
What is CVE-2021-37137?
The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was received which may lead to excessive memory usage as well. This vulnerability can be triggered by supplying malicious input that decompresses to a very big size (via a network stream or a file) or by sending a huge skippable chunk.
Is CVE-2021-37137 actively exploited?
Active exploitation of CVE-2021-37137 has not been confirmed. Its EPSS score was 6.6% on 2026-10-09, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2021-37137?
CVE-2021-37137 has a CVSS v3 base score of 7.5 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.
Is CVE-2021-37137 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2021 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).