highCVSS 7.5Vulnerability

GHSA-rcw4-f5rp-g42v

**Affected package:** adm-zip (npm) **Affected version:** 0.6.0 ## Summary The fix shipped for CVE-2026-39244 (`methods/inflater.js`) caps zlib's decompression output via `maxOutputLength: expectedLength`, where `expectedLength` is read directly from the ZIP entry's attacker-controlled "uncompressed size" header field (`CENLEN`/`LOCLEN`). This cap is only applied when `expectedLength > 0`: ```js const option = version >= 15 && expectedLength > 0 ? { maxOutputLength: expectedLength } : {}; return zlib.inflateRawSync(inbuf, option); ``` If an attacker sets the declared uncompressed-size field to exactly **0**, this condition is false, `option` becomes `{}`, and no output cap is passed to zlib at all. Node then falls back to zlib's own internal default limit (several GB), so a small, highly-compressible payload can still be decompressed to a very large size in memory -- the same class of resource-exhaustion issue the original CVE addressed, just triggered differently. ## Steps to Reproduce 1. Build a ZIP archive containing one DEFLATE-compressed entry whose real content is highly redundant (e.g. several MB of a repeated byte, achieving close to the ~1032:1 theoretical raw-DEFLATE compression ratio). 2. Patch the entry's declared uncompressed-size fields (both the local file header copy and the central directory copy, 4-byte little-endian values) to `0`. The compressed bytes and CRC32 are left untouched -- CRC validation still passes because CRC is computed over the real decompressed output, not the declared size. 3. Load the archive with `new AdmZip(buffer)` and call `.getEntries()[0].getData()` (or `readFile`/`readAsText`/`extractAllTo`/etc. -- all share the same code path). 4. Observe: decompression succeeds and returns the full-size buffer with no size restriction applied, whereas the same real data with an honest (but undersized) declared value correctly throws `Cannot create a Buffer larger than N bytes`. ## Proof of Concept Attached script demonstrates a

Properties

severity
high
summary
adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
cvss_score
7.5
retrieved_at
2026-09-29T22:26:28+00:00
ghsa_published
2026-09-29T18:25:20Z
source_url
https://github.com/advisories/GHSA-rcw4-f5rp-g42v
ghsa_updated
2026-09-29T18:25:21Z
ghsa_id
GHSA-rcw4-f5rp-g42v
last_source
GitHub Advisory Database
cve_id
GHSA-rcw4-f5rp-g42v
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-29T22:18:34+00:00
is_ghsa_only
true

Related Entities (4)

VULNERABLE_TO (1)

←[Software]npm/adm-zip

AFFECTS (1)

→[Software]npm/adm-zip

HAS_WEAKNESS (1)

→[Weakness]Improper Handling of Highly Compressed Data (Data Amplification)

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-rcw4-f5rp-g42v (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal