Intel

AIKIDO-2025-10303

commons-asic is vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

Improper Handling of Highly Compressed Data (Data Amplification) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 12, 2025

40

Medium Risk

This Affects:

Javacommons-asic
0.9.4 - 1.0.0
Fixed in 1.0.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package lack proper ZipBomb protection, failing to enforce size limits on meta-inf files during extraction. An attacker can exploit this vulnerability by crafting a malicious ZIP archive containing excessively large meta-inf files, which, when processed, overwhelms system resources (e.g., disk space or memory) due to uncontrolled extraction.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

commons-asic is vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) in versions 0.9.4 - 1.0.0.

How to fix this

Upgrade the no.difi.commons:commons-asic library to the patch version.