CVE-2026-39244Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntry.js line 103, Buffer.alloc(_centralHeader.size) allocates memory based on the declared uncompressed size from the ZIP central directory header without validating it against the actual compressed data size or imposing any upper bound. The size value is read directly from the binary header at entryHeader.js line 266 with no bounds check. An attacker can craft a ~120-byte ZIP file that declares ~4GB uncompressed size, causing a memory allocation amplification ratio of over 33 million to 1. The allocation occurs before CRC validation, so the malicious payload cannot be rejected early. All extraction and read methods are affected: readFile(), readAsText(), extractEntryTo(), extractAllTo(), extractAllToAsync(), test(), and entry.getData(). Any application accepting untrusted ZIP files via adm-zip is vulnerable to immediate process crash.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-11); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-11: 1Mentions · 2026-09-30: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-11: 107-1109-30
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse2 posts
  • DailyCVE@dailycve

    🔴 adm-zip, Async Decompression Denial of Service, #CVE-2026-39244-related (Critical) -DC-Sep2026-2635 https://dailycve.com/adm-zip-async-decompression-denial-of-service-cve-2026-39244-related-critical-dc-sep2026-2635/

    0101053
    239 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - ZIP central directory size spoofing leads to memory exhaustion DoS (CVE-2026-39244) A denial-of-service vulnerability affects the Node.js ZIP handling library adm-zip when parsing crafted ZIP files with a manipulated “uncompressed size” in the central directory header. The root cause is improper input validation/bounds checking, where the library trusts the declared uncompressed size and allocates memory accordingly. An attacker can exploit this by supplying a small, malicious ZIP to any service or app that reads or extracts untrusted ZIP content via adm-zip methods, with no special privileges beyond getting the file processed. Impact is process memory exhaustion and crashes from multi-gigabyte allocations, resulting in service disruption and potential cascading failures in ZIP-processing pipelines. 👉 Affected: adm-zip < 0.5.18 | Upgrade to 0.5.18

    Post summary

    The post discloses a denial‑of‑service vulnerability in the Node.js adm‑zip library (CVE‑2026‑39244) caused by ZIP central directory size spoofing, and recommends upgrading to version 0.5.18.

    00010104
    247 followersView on X

Explore more