adm-zip is vulnerable to Denial of Service (DoS)
75
High Risk
adm-zip caps decompression output at an entry's declared uncompressed size to limit decompression bombs, but skips the cap entirely when the declared size is 0. A crafted archive that declares its uncompressed size as zero decompresses without any limit, so a tiny payload expands to gigabytes and exhausts memory. This bypasses the earlier decompression-bomb protection. The fix enforces a minimum one-byte cap so a zero-size declaration can no longer disable the limit.
You are affected if you are using a version that falls within the vulnerable range.
adm-zip is vulnerable to Denial of Service (DoS) in versions 0.5.14 - 0.6.0.
Upgrade the adm-zip library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.