High severity7.5NVD Advisory· Published Sep 15, 2026
CVE-2026-92000
CVE-2026-92000
Description
adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/cthackers/adm-zip/blob/v0.6.0/methods/inflater.jsnvd
- github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6nvd
- github.com/cthackers/adm-zip/commit/8bc411184de1b5ca28138c53074fb61119994ddenvd
- github.com/cthackers/adm-zip/security/advisories/GHSA-rcw4-f5rp-g42vnvd
- www.vulncheck.com/advisories/adm-zip-0.5.14-through-0.6.0-denial-of-service-via-zero-declared-uncompressed-sizenvd
News mentions
0No linked articles in our index yet.