Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-77301— adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)

Quick assessment

Affected
cthackers adm-zip
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

adm-zip 是一个用于在 Node.js 中创建和解压 ZIP 归档的 JavaScript 库。在 0.6.1 版本之前,zipEntry.js 中的 函数会直接信任 ZIP 条目中心目录中声明的“未压缩大小”,并在验证该值与实际压缩数据及解压结果之前,就提前分配输出内存。攻击者可以构造一个小型的恶意 ZIP 文件,在其中声明一个高达数 GB 的未压缩大小,导致 和压缩数据处理在 CRC 校验报错之前就已分配了过多的常驻内存。因此,应用程序若读取来自不受信任归档文件的条目,可能会因操作系统强制终止进程或导致整

CVSS 7.5 · High EPSS 0.61% · P47

Possible ATT&CK Techniques 1 AI

T1527

Affected Version Matrix 1

VendorProduct Version RangeStatus
cthackers adm-zip < 0.6.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77301

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
Source: CVE Program / CVE List V5
Vulnerability Description
adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEntry.js trusts an entry's central-directory uncompressed size and allocates output memory before validating that value against the actual compressed data and decompression result. A small crafted ZIP can declare a multi-gigabyte uncompressed size, causing Buffer.alloc and decompression handling to commit excessive resident memory before CRC validation reports an error. Applications that read entries from untrusted archives can therefore be terminated by the operating system or suffer service-wide memory exhaustion. This issue is fixed in version 0.6.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的内存分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
cthackers adm-zip < 0.6.1 -

II. Public POCs for CVE-2026-77301

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77301

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-77301 (1)

Other References for CVE-2026-77301 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-77301

No comments yet


Leave a comment