adm-zip Decompression Bomb Protection Bypass
The adm-zip Node.js library fails to enforce memory limits during decompression when the ZIP entry uncompressed size header is set to zero, enabling potential memory exhaustion attacks.
CVE search metadata
CVE search record: CVE-2026-39244. Severity: high. CVSS: 7.5. EPSS: 0.84%. KEV: no. Product: adm-zip (<= 0.6.0). Brief: adm-zip Decompression Bomb Protection Bypass. Brief link: https://feed.craftedsignal.io/briefs/2026-09-adm-zip-bypass/
The adm-zip library for Node.js (version 0.6.0 and earlier) contains a security flaw in its decompression-bomb protection mechanism, which was intended to mitigate CVE-2026-39244. The vulnerability exists within methods/inflater.js, where a conditional check applies a maxOutputLength constraint to zlib.inflateRawSync only if the declared uncompressed size of the ZIP entry is greater than zero.
An attacker can bypass this protection by crafting a malicious ZIP archive where the declared uncompressed size field in the local file header and central directory is set to exactly 0. Because the condition expectedLength > 0 fails, the maxOutputLength option is omitted, causing the library to default to zlib's internal limits rather than the intended application-level cap. This allows a small, highly compressed payload to expand into a significantly larger buffer in memory, leading to potential denial-of-service via OOM (Out-of-Memory) conditions.
Attack Chain
- Attacker generates a highly redundant file to achieve high compression ratios (e.g., repeating bytes).
- Attacker compresses this file using the DEFLATE algorithm.
- Attacker modifies the ZIP archive structure to set both the local file header and central directory 'uncompressed size' fields to 0.
- Attacker delivers the malicious ZIP archive to a target application using adm-zip.
- The target application passes the untrusted ZIP to
new AdmZip(buffer). - The application calls
.getData(),.readFile(), or similar extraction methods on the malicious entry. - The adm-zip library ignores the
maxOutputLengthconstraint due to the 0-value size field. - Zlib decompresses the full payload into memory, resulting in excessive resource consumption and potential process termination.
Impact
The vulnerability affects any application using adm-zip to process untrusted archives, such as web upload handlers, CI/CD artifact extractors, or email gateway scanners. Successful exploitation can lead to process crashes and denial-of-service by consuming disproportionate amounts of server memory, bypassing the intended safety guards implemented against decompression bombs.
Recommendation
- Upgrade the
adm-zippackage to a version that implements unconditionalmaxOutputLengthenforcement or adds an independent compression-ratio verification mechanism. - Until an upgrade is available, implement a wrapper around
adm-zipfunctions that validates the actual size of the output buffer against a strict absolute ceiling before returning it to the application logic. - Monitor logs for unusual memory spikes or process crashes associated with ZIP processing modules.
Immediate actions
Upgrade adm-zip to 0.5.18 or later
Mitigations
Validate uncompressed size and compression ratios independently before passing data to adm-zip functions.
CVE-2026-39244