Description
adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value against the actual compressed data and decompression result. A small crafted ZIP can declare a multi-gigabyte uncompressed size, causing Buffer.alloc and decompression handling to commit excessive resident memory before CRC validation reports an error. Applications that read entries from untrusted archives can therefore be terminated by the operating system or suffer service-wide memory exhaustion. This issue is fixed in version 0.6.1.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via uncontrolled memory allocation
Action: Patch to 0.6.1
AI Analysis

Impact

adm-zip is a Node.js library that reads ZIP archives. In versions earlier than 0.6.1 the getData() method allocates a buffer using the uncompressed size reported in the ZIP central directory without verifying that it matches the actual decompressed size. A maliciously crafted ZIP can declare a multi‑gigabyte uncompressed size, forcing Buffer.alloc and the decompression routine to allocate large amounts of memory before detecting the CRC error. This can exhaust system memory, cause the operating system to kill the process, or lead to prolonged resource starvation, effectively disabling the application.

Affected Systems

The vulnerability affects the adm-zip package supplied by cthackers. Any Node.js application that imports and uses adm-zip prior to version 0.6.1 is susceptible. This includes libraries or web applications that accept uploads of ZIP files from untrusted users.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. An EPSS score of <1% and the fact that the flaw is not listed in CISA KEV suggest no confirmed widespread exploitation. However, the issue can be exploited remotely if an application accepts ZIPs from external parties. Attackers can craft a malicious archive, host it, and trigger the vulnerability by having the target application process the archive, leading to memory exhaustion or termination of the process. The lack of input validation and the direct buffer allocation make the attack straightforward for a knowledgeable adversary.

Generated by OpenCVE AI on September 23, 2026 at 01:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade adm‑zip to version 0.6.1 or later.
  • If an immediate upgrade is not viable, enforce strict memory limits on the Node.js process or run the ZIP extraction in a sandboxed environment with clearly defined resource constraints.
  • Add a runtime check that the declared uncompressed size does not exceed a safe threshold before allocating memory or performing decompression.

Generated by OpenCVE AI on September 23, 2026 at 01:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7q85-xj36-vmfc adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Cthackers
Cthackers adm-zip
Vendors & Products Cthackers
Cthackers adm-zip

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value against the actual compressed data and decompression result. A small crafted ZIP can declare a multi-gigabyte uncompressed size, causing Buffer.alloc and decompression handling to commit excessive resident memory before CRC validation reports an error. Applications that read entries from untrusted archives can therefore be terminated by the operating system or suffer service-wide memory exhaustion. This issue is fixed in version 0.6.1.
Title adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Cthackers Adm-zip
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:11:11.964Z

Reserved: 2026-08-20T19:17:14.375Z

Link: CVE-2026-77301

cve-icon Vulnrichment

Updated: 2026-09-18T17:11:03.081Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T17:17:00.507

Modified: 2026-09-24T21:16:28.120

Link: CVE-2026-77301

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T16:38:47Z

Links: CVE-2026-77301 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T02:00:10Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling

  • CWE-789

    Memory Allocation with Excessive Size Value