Executive brief
adm-zip is a popular JavaScript library for creating and extracting ZIP files in Node.js applications. Versions 0.5.14 through 0.6.0 contain a flaw that allows attackers to craft specially crafted ZIP archives with highly compressed entries that declare zero uncompressed size. When these malicious archives are processed, the application can exhaust server memory and crash, leading to denial of service and potential business disruption.
Technical details
The vulnerability is a denial-of-service flaw in adm-zip's zlib decompression handling. When ZIP entries declare zero uncompressed size, the library fails to apply proper output limits during decompression, allowing an attacker to craft highly compressible (zip-bomb-style) archives that decompress to enormous sizes in memory. The attack is network-accessible if the application processes untrusted ZIP files, and requires no authentication. An attacker can trigger out-of-memory conditions and crash the application. The vulnerability affects versions 0.5.14 through 0.6.0; patched versions beyond 0.6.0 are believed to be available.
Affected products
- cthackers adm-zip 0.5.14 through 0.6.0
Timeline
- 2026-09-15: disclosed