Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

GHSA-RCW4-F5RP-G42V: GHSA-RCW4-F5RP-G42V: Uncontrolled Resource Consumption and Decompression Bomb Protection Bypass in adm-zip

GHSA-RCW4-F5RP-G42V: Uncontrolled Resource Consumption and Decompression Bomb Protection Bypass in adm-zip Vulnerability ID: GHSA-RCW4-F5RP-G42V CVSS Score: 7.5 Published: 2026-09-29 A critical denial-of-service vul

GHSA-RCW4-F5RP-G42V: Uncontrolled Resource Consumption and Decompression Bomb Protection Bypass in adm-zip

Vulnerability ID: GHSA-RCW4-F5RP-G42V
CVSS Score: 7.5
Published: 2026-09-29

A critical denial-of-service vulnerability in the adm-zip npm package allows attackers to bypass decompression-bomb protections introduced in version 0.5.18. By declaring the uncompressed file size as exactly 0, an attacker can disable the maxOutputLength constraint in the Node.js zlib wrapper, leading to complete system memory exhaustion and process crashes.

TL;DR

A bypass of the decompression bomb protection in adm-zip (CVE-2026-39244) allows attackers to trigger out-of-memory crashes by setting the declared uncompressed size header of a malicious ZIP entry to 0, which disables zlib limits.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400 (Uncontrolled Resource Consumption)
  • Attack Vector: Network / Remote
  • CVSS Score: 7.5 (High)
  • Exploit Status: Proof of Concept (PoC) Available
  • KEV Status: Not Listed

Affected Systems

  • Applications utilizing adm-zip to parse, read, or decompress ZIP archives
  • adm-zip: >= 0.5.18 < 0.6.1 (Fixed in: 0.6.1)
  • adm-zip: < 0.5.18 (Fixed in: 0.5.18)

Code Analysis

Commit: 2450dcf

Fix CVE-2026-39244 by removing direct pre-allocation and setting maxOutputLength

Commit: 4916006

Fix GHSA-RCW4-F5RP-G42V by enforcing a minimum boundary cap of 1 and manual streaming boundaries

Exploit Details

  • GitHub Issue #568: Vulnerability report and discussion of the uncontrolled memory allocation mechanism.

Mitigation Strategies

  • Upgrade adm-zip package to version 0.6.1 or above to enforce stream caps.
  • Deploy container-level memory limits (e.g., Docker memory limits) to prevent system-wide crashes.
  • Sanitize file upload formats and restrict maximum file upload size at the gateway layer (e.g., NGINX client_max_body_size).

Remediation Steps:

  1. Open package.json and locate the adm-zip entry under dependencies.
  2. Update the version string to ^0.6.1.
  3. Run npm install or yarn install to apply the dependency patch.
  4. Validate the fix by executing the regression scripts in a staging environment.

References

Read the full report for GHSA-RCW4-F5RP-G42V on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.