highCVSS 7.5Vulnerability

CVE-2026-77301

### Summary adm-zip allocates an entry's output buffer from the declared uncompressed size (central-directory `size` field) before validating it against the actual data. A tiny crafted ZIP that declares a huge uncompressed size forces a multi-gigabyte allocation from a few bytes. ### Impact On adm-zip 0.5.17 (latest), Node 24, a 105-byte ZIP with one stored entry declaring size = 1,774,399,200 makes `new AdmZip(buf).getEntries()[0].getData()` commit ~1.8 GB of resident memory in ~4.4 s before throwing `Error: ADM-ZIP: CRC32 checksum failed`, roughly 16 million times the input size. Because the buffer is committed before any validation, on a memory-constrained host (containers, serverless, small VMs) the allocation OOM-kills the process before the CRC check (uncatchable), and concurrent requests can exhaust memory even on larger hosts. Any service that reads entries from untrusted ZIPs is exposed to a remote denial of service. ### Steps to reproduce Attachments are not supported in the advisory form, so the 105-byte PoC (sha256 `980d34356fbb248fe527b9d0ac3eabc5c99393a374014be6199523de16709386`) is inlined as base64 in this self-contained reproducer: ```js const AdmZip = require('adm-zip'); // 105-byte crafted ZIP, base64-inlined // sha256 980d34356fbb248fe527b9d0ac3eabc5c99393a374014be6199523de16709386 const b64 = "UEsDBBQAAAAAAAAAAAAAAAAABQAAAAUAAAABAAAAYWhlbGxvUEsBAhQAFAAAAAAAAAAAAAAAAAAFAAAA4C7DaQEAAAAAAAAAAAAAAAAAAAAAAGFQSwUGAAAAAAEAAQAvAAAAJAAAAAAA"; const buf = Buffer.from(b64, "base64"); // 105 bytes const zip = new AdmZip(buf); zip.getEntries()[0].getData(); // commits ~1.8 GB, then throws "ADM-ZIP: CRC32 checksum failed" ``` The single entry declares uncompressed size = 1,774,399,200 with a compressed size of 5. `getData()` allocates the full declared size before the CRC check runs, so the memory is committed regardless of the (tiny) actual payload. ### Root cause `zipEntry.js` does `Buffer.alloc(<declared uncompressed size>)` before checking

Properties

ghsa_id
GHSA-7q85-xj36-vmfc
severity
high
summary
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
cvss_score
7.5
cve_id
CVE-2026-77301
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-18T17:46:44+00:00
is_ghsa_only
false
ghsa_published
2026-09-18T17:18:01Z
source_url
https://github.com/advisories/GHSA-7q85-xj36-vmfc
ghsa_updated
2026-09-18T17:18:03Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]npm/adm-zip

AFFECTS (1)

[Software]npm/adm-zip

HAS_WEAKNESS (1)

[Weakness]Memory Allocation with Excessive Size Value

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77301 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal