highCVSS 7.5Vulnerability

GHSA-8238-w5pm-2374

## Summary Denial of Service in `adm-zip`'s async decompression API allows an unauthenticated attacker to crash the entire Node.js host process by supplying a single malformed ZIP file. ## Details **Affected package**: adm-zip **Affected versions**: at least 0.6.0 (current latest); likely all versions containing the current `inflateAsync` implementation in `methods/inflater.js` **Patched version**: 0.6.1 ### Root Cause `methods/inflater.js:12-32` (`inflateAsync`) creates a `zlib.createInflateRaw(option)` stream and feeds it attacker-controlled compressed bytes via `tmp.end(inbuf)`, but never registers an `"error"` listener on the stream: ```js inflateAsync: function (/*Function*/ callback) { var tmp = zlib.createInflateRaw(option), parts = [], total = 0; tmp.on("data", function (data) { parts.push(data); total += data.length; }); tmp.on("end", function () { /* build buf, callback(buf) */ }); tmp.end(inbuf); // no tmp.on("error", ...) registered anywhere } ``` Per Node.js `EventEmitter`/stream semantics, an `"error"` event emitted with zero listeners is rethrown as an **uncaught exception on a later tick**, originating from the zlib C++ binding. This cannot be caught by a `try/catch` wrapped around the calling code, because the throw happens asynchronously, outside the synchronous call stack the `try/catch` covers. This code path is reached from every public async API that decompresses entry data: `readFileAsync`, `readAsTextAsync`, `extractAllToAsync`, and `ZipEntry.getDataAsync` (`zipEntry.js:51`, `:97-120`, `:309-315`; `adm-zip.js:157-164`, `:192-210`, `:893`). This library recently patched **CVE-2026-39244** (GHSA-xcpc-8h2w-3j85), an unbounded `Buffer.alloc()` on the *synchronous* decompression path. That fix added a `maxOutputLength` option to `zlib.inflateRawSync`/`zlib.createInflateRaw`, and the sync path's resulting throw is naturally catchable. The async path shares the same `maxOutputLength` option (`methods/inflat

Properties

summary
adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)
severity
high
cvss_score
7.5
retrieved_at
2026-09-30T02:27:15+00:00
ghsa_published
2026-09-29T23:10:09Z
source_url
https://github.com/advisories/GHSA-8238-w5pm-2374
ghsa_updated
2026-09-29T23:10:11Z
ghsa_id
GHSA-8238-w5pm-2374
last_source
GitHub Advisory Database
cve_id
GHSA-8238-w5pm-2374
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-30T02:27:15+00:00
is_ghsa_only
true

Related Entities (5)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/adm-zip

AFFECTS (1)

→[Software]npm/adm-zip

HAS_WEAKNESS (2)

→[Weakness]Uncontrolled Resource Consumption
→[Weakness]Uncaught Exception

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-8238-w5pm-2374 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal