CVE-2026-92000
adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.
Zwakheid
adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.
Bronnen
- https://github.com/cthackers/adm-zip
- https://github.com/cthackers/adm-zip/blob/v0.6.0/methods/inflater.js
- https://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6
- https://github.com/cthackers/adm-zip/commit/8bc411184de1b5ca28138c53074fb61119994dde
- https://github.com/cthackers/adm-zip/security/advisories/GHSA-rcw4-f5rp-g42v
- https://www.vulncheck.com/advisories/adm-zip-0.5.14-through-0.6.0-denial-of-service-via-zero-declared-uncompressed-size
Vind de bug voordat een aanvaller dat doet.
Log in met GitHub en start je eerste audit binnen een minuut. Voor het gratis abonnement is geen creditcard nodig.