adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 21:16
Updated : 2026-09-15 21:16
NVD link : CVE-2026-92000
Mitre link : CVE-2026-92000
CVE.ORG link : CVE-2026-92000
JSON object : View
Products Affected
No product.
CWE
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
