CVE-2026-45820 — fflate
Fix: 101arrowz/fflate@e6d5e6eCVE-2026-45820 is a Uncontrolled Resource Consumption vulnerability in fflate. A fix is available for fflate — see the affected versions and patch details below.
fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives
Exploitation Status
No confirmed exploitation observed yet
- CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-45820.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
fflatenpmDescription
fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces to 0, keeping the loop condition permanently true.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | fflate | ≥ 0.4.5&&< 0.4.9 | 0.4.9npm install fflate@0.4.9 |
| 📦npm | fflate | ≥ 0.5.0&&< 0.5.4 | 0.5.4npm install fflate@0.5.4 |
| 📦npm | fflate | ≥ 0.6.0&&< 0.6.11 | 0.6.11npm install fflate@0.6.11 |
| 📦npm | fflate | ≥ 0.7.0&&< 0.7.5 | 0.7.5npm install fflate@0.7.5 |
| 📦npm | fflate | ≥ 0.8.0&&< 0.8.3 | 0.8.3npm install fflate@0.8.3 |
Affected Products
fflate101arrowzDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for fflate, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update fflate to 0.4.9 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-45820 is resolved across your whole dependency graph.
Workarounds
Stop feeding it untrusted input: reject or quarantine files and payloads from unverified sources until you can upgrade, restrict accepted formats to the ones you actually need, and run the parsing or decoding step in a least-privileged sandbox or short-lived worker so a crash or corrupted read cannot reach the rest of the process.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
This CVE describes a denial-of-service flaw in the fflate JavaScript compression library. Parsing a maliciously crafted ZIP archive via unzipSync()/unzip() triggers an infinite loop in the ZIP64 central-directory parser (z64e): a central directory entry declaring the ZIP64 size sentinel (0xFFFFFFFF) but omitting the…
There is no available mitigation for this flaw other than updating the bundled fflate library to a fixed version (0.8.3 or later). Where the application controls the input, avoid passing untrusted ZIP archives to fflate's unzip()/unzipSync() APIs.Source: Red Hat security advisory for CVE-2026-45820 (CC BY 4.0)
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat OpenShift Service Mesh 3.3 | openshift-service-mesh/kiali-ossmc-rhel9:1789050085 | RHSA-2026:68690 |
| Red Hat OpenShift Service Mesh 3.4 | openshift-service-mesh/kiali-ossmc-rhel9:1789475294 | RHSA-2026:68695 |
Frequently Asked Questions
Is CVE-2026-45820 in your dependencies?
Find it across npm, including transitive dependencies.