Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-32630

Опубликовано: 16 мар. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excessive memory growth during type detection in file-type when using fileTypeFromBuffer(), fileTypeFromBlob(), or fileTypeFromFile(). The ZIP inflate output limit is enforced for stream-based detection, but not for known-size inputs. As a result, a small compressed ZIP can cause file-type to inflate and process a much larger payload while probing ZIP-based formats such as OOXML. This vulnerability is fixed in 21.3.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sindresorhus:file-type:*:*:*:*:*:node.js:*:*
Версия от 20.0.0 (включая) до 21.3.2 (исключая)

EPSS

Процентиль: 22%
0.00299
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-409

Связанные уязвимости

CVSS3: 5.3
redhat
5 месяцев назад

file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excessive memory growth during type detection in file-type when using fileTypeFromBuffer(), fileTypeFromBlob(), or fileTypeFromFile(). The ZIP inflate output limit is enforced for stream-based detection, but not for known-size inputs. As a result, a small compressed ZIP can cause file-type to inflate and process a much larger payload while probing ZIP-based formats such as OOXML. This vulnerability is fixed in 21.3.2.

CVSS3: 5.3
github
5 месяцев назад

file-type: ZIP Decompression Bomb DoS via [Content_Types].xml entry

EPSS

Процентиль: 22%
0.00299
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-409