Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-92000

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

A flaw was found in adm-zip. A remote attacker could exploit this vulnerability by crafting a malicious ZIP archive containing highly compressible entries that declare a zero uncompressed size. This oversight prevents the application of zlib decompression output limits, leading to excessive memory consumption and ultimately a Denial of Service (DoS) condition.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-operator-bundleNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Not affected
Red Hat Build of Podman Desktoprh-podman-desktop.gitAffected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Affected
Red Hat Enterprise Linux 8mozjs60Affected
Red Hat Enterprise Linux 9gjsAffected
Red Hat Fuse 7adm-zipWill not fix
Red Hat OpenShift AI (RHOAI)rhoai/odh-core-bff-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-dashboard-operator-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-dashboard-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2534417adm-zip: adm-zip: Denial of Service via crafted ZIP archives with zero declared uncompressed size

EPSS

Процентиль: 33%
0.00388
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
4 дня назад

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

CVSS3: 7.5
github
4 дня назад

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives with highly compressible entries declaring zero size to exhaust memory and cause denial of service.

EPSS

Процентиль: 33%
0.00388
Низкий

7.5 High

CVSS3