---
id: CVE-2026-92000
title: >-
  adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output
  limits when ZIP entries declare zero uncompressed size
summary: >-
  adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output
  limits when ZIP entries declare zero uncompressed size. Attackers can craft
  malicious ZIP archives with highly compressible entries declaring zero size to
  exha…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-409
  - CWE-770
vendor: cthackers
product: adm-zip
affected:
  - adm-zip >= 0.5.14 < 0.6.1
published: '2026-09-15'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92000'
references:
  - url: 'https://github.com/cthackers/adm-zip'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/cthackers/adm-zip/blob/v0.6.0/methods/inflater.js'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/cthackers/adm-zip/commit/491600683dacb6cb9fe0718a0eeb9cb5eb49afa6
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/cthackers/adm-zip/commit/8bc411184de1b5ca28138c53074fb61119994dde
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/cthackers/adm-zip/security/advisories/GHSA-rcw4-f5rp-g42v
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/adm-zip-0.5.14-through-0.6.0-denial-of-service-via-zero-declared-uncompressed-size
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92000.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-92000'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2534417'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-92000'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92000'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00684
epssPercentile: 0.50446
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T19:15:34.853950Z'
ingestedAt: '2026-09-15T21:44:50.655Z'
---

## Overview

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Important · affected: Red Hat Build of Podman Desktop, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Fuse 7, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, … · no fix planned: Red Hat Fuse 7, Red Hat Build of Podman Desktop, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92000.json)
