Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service. | |
| Title | adm-zip 0.5.14 through 0.6.0 Denial of Service via Zero Declared Uncompressed Size | |
| First Time appeared |
Adm-zip Project
Adm-zip Project adm-zip |
|
| Weaknesses | CWE-409 | |
| CPEs | cpe:2.3:a:adm-zip_project:adm-zip:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Adm-zip Project
Adm-zip Project adm-zip |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T20:56:45.780Z
Reserved: 2026-09-15T11:12:09.501Z
Link: CVE-2026-92000
No data.
Status : Received
Published: 2026-09-15T21:16:49.167
Modified: 2026-09-15T21:16:49.167
Link: CVE-2026-92000
No data.
OpenCVE Enrichment
No data.
-
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)