Intel

AIKIDO-2026-272676

adm-zip is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-92000 Published Today

75

High Risk

This Affects:

JSadm-zip
0.5.14 - 0.6.0
Fixed in 0.6.1
Are you affected? Scan for Free

TL;DR

adm-zip caps decompression output at an entry's declared uncompressed size to limit decompression bombs, but skips the cap entirely when the declared size is 0. A crafted archive that declares its uncompressed size as zero decompresses without any limit, so a tiny payload expands to gigabytes and exhausts memory. This bypasses the earlier decompression-bomb protection. The fix enforces a minimum one-byte cap so a zero-size declaration can no longer disable the limit.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

adm-zip is vulnerable to Denial of Service (DoS) in versions 0.5.14 - 0.6.0.

How to fix this

Upgrade the adm-zip library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform