High severity7.5NVD Advisory· Published Jul 22, 2026· Updated Aug 19, 2026
CVE-2026-45820
CVE-2026-45820
Description
fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces to 0, keeping the loop condition permanently true.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
fflatenpm | >= 0.4.5, < 0.4.9 | 0.4.9 |
fflatenpm | >= 0.5.0, < 0.5.4 | 0.5.4 |
fflatenpm | >= 0.6.0, < 0.6.11 | 0.6.11 |
fflatenpm | >= 0.7.0, < 0.7.5 | 0.7.5 |
fflatenpm | >= 0.8.0, < 0.8.3 | 0.8.3 |
Affected products
8- osv-coords7 versionspkg:apk/chainguard/lambda-nodejs24pkg:apk/chainguard/langfuse-4-workerpkg:apk/chainguard/lambda-nodejs22pkg:apk/chainguard/langfuse-fips-4-workerpkg:apk/chainguard/librechatpkg:apk/chainguard/tileserver-glpkg:apk/wolfi/tileserver-gl
< 4.0.2-r2+ 6 more
- (no CPE)range: < 4.0.2-r2
- (no CPE)range: < 4.27.0-r4
- (no CPE)range: < 4.0.2-r2
- (no CPE)range: < 4.28.1-r1
- (no CPE)range: < 0.8.7-r12
- (no CPE)range: < 5.6.0-r15
- (no CPE)range: < 5.6.0-r15
Patches
Vulnerability mechanics
References
6- github.com/101arrowz/fflate/blob/f7873560ad229c22c4b23b06c6a3806ffde77569/src/index.tsnvdPatchWEB
- github.com/advisories/GHSA-px8p-9vwx-vf98ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-45820ghsaADVISORY
- github.com/101arrowz/fflate/commit/e6d5e6e1076892f72770ac732d83c81da9f3316eghsaWEB
- github.com/101arrowz/fflate/releases/tag/v0.8.3ghsaWEB
- www.npmjs.com/package/fflatenvdProduct
News mentions
0No linked articles in our index yet.