VDB
CVE-2026-92000
CVE-2026-92000
PUBLISHED
CVSS 8.7 HIGH
Reported by VulnCheck · Published September 15, 2026
adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.
Risk Scores
CVSS 4.0
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cthackers | adm-zip | 0.5.14 |
| cthackers | adm-zip | 0.5.14, 0.5.14, 0.5.14 |
| adm-zip_project | adm-zip | 0.5.14, 0.5.14, 0.5.14 |
| cthackers | adm-zip |
Timeline
- Sep 15, 2026 CVE Published
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 24, 2026 CVE Updated
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
- Oct 6, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-rcw4-f5rp-g42v) vendor-advisory
- Fix commit (0.6.1) patch
- Commit introducing the conditional cap (0.5.14) technical-descriptionpatch
- Vulnerable inflater.js at v0.6.0 technical-description
- product
- VulnCheck Advisory: adm-zip 0.5.14 through 0.6.0 Denial of Service via Zero Declared Uncompressed Size third-party-advisory