Denial of Service in adm-zip by CTHackers
CVE-2026-92000

8.7HIGH

Key Information:

Vendor

Cthackers

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-92000?

The adm-zip library versions 0.5.14 through 0.6.0 are vulnerable to denial of service attacks due to a failure to enforce zlib decompression output limits. Attackers can exploit this vulnerability by creating malicious ZIP files that declare zero uncompressed size, leading to potential memory exhaustion. This can cause applications relying on adm-zip to crash or become unresponsive. It is critical for users to upgrade to version 0.6.1 or later, where this issue has been addressed.

Affected Version(s)

adm-zip 0.5.14 < 0.6.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dilipkumar Choudhary
.