adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 15 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service. | |
| Title | adm-zip 0.5.14 through 0.6.0 Denial of Service via Zero Declared Uncompressed Size | |
| First Time appeared |
Adm-zip Project
Adm-zip Project adm-zip |
|
| Weaknesses | CWE-409 | |
| CPEs | cpe:2.3:a:adm-zip_project:adm-zip:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Adm-zip Project
Adm-zip Project adm-zip |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T20:56:45.780Z
Reserved: 2026-09-15T11:12:09.501Z
Link: CVE-2026-92000
No data.
Status : Received
Published: 2026-09-15T21:16:49.167
Modified: 2026-09-15T21:16:49.167
Link: CVE-2026-92000
No data.
OpenCVE Enrichment
No data.
Weaknesses