<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Adm-Zip - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/adm-zip/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 22:18:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/adm-zip/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>adm-zip Decompression Bomb Protection Bypass</title><link>https://feed.craftedsignal.io/briefs/2026-09-adm-zip-bypass/</link><pubDate>Tue, 29 Sep 2026 22:18:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-adm-zip-bypass/</guid><description>The adm-zip Node.js library fails to enforce memory limits during decompression when the ZIP entry uncompressed size header is set to zero, enabling potential memory exhaustion attacks.</description><content:encoded><![CDATA[<p>The adm-zip library for Node.js (version 0.6.0 and earlier) contains a security flaw in its decompression-bomb protection mechanism, which was intended to mitigate CVE-2026-39244. The vulnerability exists within <code>methods/inflater.js</code>, where a conditional check applies a <code>maxOutputLength</code> constraint to <code>zlib.inflateRawSync</code> only if the declared uncompressed size of the ZIP entry is greater than zero.</p>
<p>An attacker can bypass this protection by crafting a malicious ZIP archive where the declared uncompressed size field in the local file header and central directory is set to exactly 0. Because the condition <code>expectedLength &gt; 0</code> fails, the <code>maxOutputLength</code> option is omitted, causing the library to default to zlib's internal limits rather than the intended application-level cap. This allows a small, highly compressed payload to expand into a significantly larger buffer in memory, leading to potential denial-of-service via OOM (Out-of-Memory) conditions.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker generates a highly redundant file to achieve high compression ratios (e.g., repeating bytes).</li>
<li>Attacker compresses this file using the DEFLATE algorithm.</li>
<li>Attacker modifies the ZIP archive structure to set both the local file header and central directory 'uncompressed size' fields to 0.</li>
<li>Attacker delivers the malicious ZIP archive to a target application using adm-zip.</li>
<li>The target application passes the untrusted ZIP to <code>new AdmZip(buffer)</code>.</li>
<li>The application calls <code>.getData()</code>, <code>.readFile()</code>, or similar extraction methods on the malicious entry.</li>
<li>The adm-zip library ignores the <code>maxOutputLength</code> constraint due to the 0-value size field.</li>
<li>Zlib decompresses the full payload into memory, resulting in excessive resource consumption and potential process termination.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects any application using adm-zip to process untrusted archives, such as web upload handlers, CI/CD artifact extractors, or email gateway scanners. Successful exploitation can lead to process crashes and denial-of-service by consuming disproportionate amounts of server memory, bypassing the intended safety guards implemented against decompression bombs.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>adm-zip</code> package to a version that implements unconditional <code>maxOutputLength</code> enforcement or adds an independent compression-ratio verification mechanism.</li>
<li>Until an upgrade is available, implement a wrapper around <code>adm-zip</code> functions that validates the actual size of the output buffer against a strict absolute ceiling before returning it to the application logic.</li>
<li>Monitor logs for unusual memory spikes or process crashes associated with ZIP processing modules.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>library</category><category>vulnerability</category><category>denial-of-service</category></item></channel></rss>