
🔴 adm-zip, Async Decompression Denial of Service, #CVE-2026-39244-related (Critical) -DC-Sep2026-2635 https://dailycve.com/adm-zip-async-decompression-denial-of-service-cve-2026-39244-related-critical-dc-sep2026-2635/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntry.js line 103, Buffer.alloc(_centralHeader.size) allocates memory based on the declared uncompressed size from the ZIP central directory header without validating it against the actual compressed data size or imposing any upper bound. The size value is read directly from the binary header at entryHeader.js line 266 with no bounds check. An attacker can craft a ~120-byte ZIP file that declares ~4GB uncompressed size, causing a memory allocation amplification ratio of over 33 million to 1. The allocation occurs before CRC validation, so the malicious payload cannot be rejected early. All extraction and read methods are affected: readFile(), readAsText(), extractEntryTo(), extractAllTo(), extractAllToAsync(), test(), and entry.getData(). Any application accepting untrusted ZIP files via adm-zip is vulnerable to immediate process crash.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE

🔴 adm-zip, Async Decompression Denial of Service, #CVE-2026-39244-related (Critical) -DC-Sep2026-2635 https://dailycve.com/adm-zip-async-decompression-denial-of-service-cve-2026-39244-related-critical-dc-sep2026-2635/

🚨 HIGH - ZIP central directory size spoofing leads to memory exhaustion DoS (CVE-2026-39244) A denial-of-service vulnerability affects the Node.js ZIP handling library adm-zip when parsing crafted ZIP files with a manipulated “uncompressed size” in the central directory header. The root cause is improper input validation/bounds checking, where the library trusts the declared uncompressed size and allocates memory accordingly. An attacker can exploit this by supplying a small, malicious ZIP to any service or app that reads or extracts untrusted ZIP content via adm-zip methods, with no special privileges beyond getting the file processed. Impact is process memory exhaustion and crashes from multi-gigabyte allocations, resulting in service disruption and potential cascading failures in ZIP-processing pipelines. 👉 Affected: adm-zip < 0.5.18 | Upgrade to 0.5.18
Post summary
The post discloses a denial‑of‑service vulnerability in the Node.js adm‑zip library (CVE‑2026‑39244) caused by ZIP central directory size spoofing, and recommends upgrading to version 0.5.18.