Medium · 4.9 Node.js & npm GHSA-7q85-xj36-vmfc CVE-2026-77301
adm-zip Denial-of-Service Flaw Lets Crafted ZIP Files Exhaust Memory (CVE-2026-77301)
adm-zip, a popular Node.js ZIP library, trusts the uncompressed-size field in a ZIP archive's central directory before allocating memory. A small crafted archive can declare a multi-gigabyte size, causing excessive memory use and potential crashes. Fixed in version 0.6.1.
AI summary
A vulnerability has been identified in adm-zip, a JavaScript library used in Node.js applications to create and extract ZIP archives. The issue allows a specially crafted, small ZIP file to cause the library to allocate an excessive amount of memory, potentially leading to a denial of service. The issue is fixed in adm-zip version 0.6.1.
What Happened
A vulnerability tracked as CVE-2026-77301 (GHSA-7q85-xj36-vmfc) was published affecting adm-zip, a JavaScript library for creating and extracting ZIP archives in Node.js. The flaw allows a small, crafted ZIP archive to cause the library to allocate an excessive amount of memory before validating the archive's contents.
Technical Cause
The root cause lies in the getData() function within zipEntry.js. This function trusts the uncompressed-size value stored in a ZIP entry's central directory and allocates output memory based on that value before verifying it against the actual compressed data and decompression result. A crafted ZIP archive can declare a multi-gigabyte uncompressed size while being small itself, causing Buffer.alloc and the decompression process to commit excessive resident memory before CRC validation detects an error. This is classified as CWE-789 (Memory Allocation with Excessive Size Value).
Why It Matters
Applications that read entries from untrusted ZIP archives using adm-zip can be terminated by the operating system or suffer service-wide memory exhaustion as a result of this flaw. This affects any service that unpacks user-supplied or otherwise untrusted ZIP files, which is a common pattern in file upload handling, data import pipelines, and similar functionality.
Affected Versions
All versions of adm-zip prior to 0.6.1 are affected. The issue is fixed in version 0.6.1.
Fixes and Mitigation
The vendor has released adm-zip version 0.6.1, which fixes this issue. Applications using adm-zip to process ZIP archives, particularly those from untrusted or external sources, should update to this version.
Recommended Action
Update adm-zip to version 0.6.1 or later. If immediate updating is not possible, consider limiting or monitoring memory usage for processes that handle untrusted ZIP archives, and avoid processing archives from unverified sources until the update is applied.
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Why this score
This issue has a CVSS base score of 7.5 (High), reflecting that it can be triggered remotely without authentication or user interaction, and results in a high impact on availability with no impact on confidentiality or integrity. The PatchBriefing score of 4.9 reflects that while the vulnerability is readily exploitable (no privileges or user interaction required, remote network access), there is no known public exploit code, no evidence of active exploitation, and no EPSS data to indicate elevated real-world exploitation likelihood. A fix is available, which also tempers the overall score.
Affected versions
- adm-zip < 0.6.1
- vulnerable
- ≥ 0.6.1
- patched
Reported fixes
The vendor has released adm-zip version 0.6.1, which fixes this issue. Applications using adm-zip to process ZIP archives, particularly those from untrusted or external sources, should update to this version.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email