{"id":"CVE-2026-92000","title":"adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size","summary":"adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exha…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-409","CWE-770"],"vendor":"cthackers","product":"adm-zip","affected":["adm-zip >= 0.5.14 < 0.6.1"],"published":"2026-09-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T20:18:55.267","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92000","references":[{"url":"https://github.com/cthackers/adm-zip","label":"disclosure@vulncheck.com"},{"url":"https://github.com/cthackers/adm-zip/blob/v0.6.0/methods/inflater.js","label":"disclosure@vulncheck.com"},{"url":"https://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6","label":"disclosure@vulncheck.com"},{"url":"https://github.com/cthackers/adm-zip/commit/8bc411184de1b5ca28138c53074fb61119994dde","label":"disclosure@vulncheck.com"},{"url":"https://github.com/cthackers/adm-zip/security/advisories/GHSA-rcw4-f5rp-g42v","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/adm-zip-0.5.14-through-0.6.0-denial-of-service-via-zero-declared-uncompressed-size","label":"disclosure@vulncheck.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92000.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-92000"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2534417"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-92000"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92000"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-17T19:15:34.853950Z"},"epss":0.00388,"epssPercentile":0.32783,"ingestedAt":"2026-09-15T21:44:50.655Z","slug":"CVE-2026-92000","body":"## Overview\n\nadm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Build of Podman Desktop, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Fuse 7, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, … · no fix planned: Red Hat Fuse 7, Red Hat Build of Podman Desktop, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92000.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}