VDB

CVE-2026-92000

CVE-2026-92000 PUBLISHED CVSS 8.7 HIGH

Reported by VulnCheck · Published September 15, 2026

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

Risk Scores

CVSS 4.0
8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
cthackersadm-zip0.5.14
cthackersadm-zip0.5.14, 0.5.14, 0.5.14
adm-zip_projectadm-zip0.5.14, 0.5.14, 0.5.14
cthackersadm-zip

Timeline

  • Sep 15, 2026 CVE Published
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 24, 2026 CVE Updated
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
  • Oct 2, 2026 EPSS Score
  • Oct 6, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›