{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/adm-zip/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:adm-zip_project:adm-zip:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-39244"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["adm-zip (\u003c= 0.6.0)"],"_cs_severities":["low"],"_cs_tags":["library","vulnerability","denial-of-service"],"_cs_type":"advisory","_cs_vendors":["adm-zip"],"content_html":"\u003cp\u003eThe adm-zip library for Node.js (version 0.6.0 and earlier) contains a security flaw in its decompression-bomb protection mechanism, which was intended to mitigate CVE-2026-39244. The vulnerability exists within \u003ccode\u003emethods/inflater.js\u003c/code\u003e, where a conditional check applies a \u003ccode\u003emaxOutputLength\u003c/code\u003e constraint to \u003ccode\u003ezlib.inflateRawSync\u003c/code\u003e only if the declared uncompressed size of the ZIP entry is greater than zero.\u003c/p\u003e\n\u003cp\u003eAn attacker can bypass this protection by crafting a malicious ZIP archive where the declared uncompressed size field in the local file header and central directory is set to exactly 0. Because the condition \u003ccode\u003eexpectedLength \u0026gt; 0\u003c/code\u003e fails, the \u003ccode\u003emaxOutputLength\u003c/code\u003e option is omitted, causing the library to default to zlib's internal limits rather than the intended application-level cap. This allows a small, highly compressed payload to expand into a significantly larger buffer in memory, leading to potential denial-of-service via OOM (Out-of-Memory) conditions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker generates a highly redundant file to achieve high compression ratios (e.g., repeating bytes).\u003c/li\u003e\n\u003cli\u003eAttacker compresses this file using the DEFLATE algorithm.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the ZIP archive structure to set both the local file header and central directory 'uncompressed size' fields to 0.\u003c/li\u003e\n\u003cli\u003eAttacker delivers the malicious ZIP archive to a target application using adm-zip.\u003c/li\u003e\n\u003cli\u003eThe target application passes the untrusted ZIP to \u003ccode\u003enew AdmZip(buffer)\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe application calls \u003ccode\u003e.getData()\u003c/code\u003e, \u003ccode\u003e.readFile()\u003c/code\u003e, or similar extraction methods on the malicious entry.\u003c/li\u003e\n\u003cli\u003eThe adm-zip library ignores the \u003ccode\u003emaxOutputLength\u003c/code\u003e constraint due to the 0-value size field.\u003c/li\u003e\n\u003cli\u003eZlib decompresses the full payload into memory, resulting in excessive resource consumption and potential process termination.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects any application using adm-zip to process untrusted archives, such as web upload handlers, CI/CD artifact extractors, or email gateway scanners. Successful exploitation can lead to process crashes and denial-of-service by consuming disproportionate amounts of server memory, bypassing the intended safety guards implemented against decompression bombs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003eadm-zip\u003c/code\u003e package to a version that implements unconditional \u003ccode\u003emaxOutputLength\u003c/code\u003e enforcement or adds an independent compression-ratio verification mechanism.\u003c/li\u003e\n\u003cli\u003eUntil an upgrade is available, implement a wrapper around \u003ccode\u003eadm-zip\u003c/code\u003e functions that validates the actual size of the output buffer against a strict absolute ceiling before returning it to the application logic.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual memory spikes or process crashes associated with ZIP processing modules.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T22:18:15Z","date_published":"2026-09-29T22:18:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-adm-zip-bypass/","summary":"The adm-zip Node.js library fails to enforce memory limits during decompression when the ZIP entry uncompressed size header is set to zero, enabling potential memory exhaustion attacks.","title":"adm-zip Decompression Bomb Protection Bypass","url":"https://feed.craftedsignal.io/briefs/2026-09-adm-zip-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Adm-Zip","version":"https://jsonfeed.org/version/1.1"}