{"id":"CVE-2026-45820","aliases":["GHSA-px8p-9vwx-vf98"],"url":"https://o3.security/vulnerability/CVE-2026-45820","summary":"fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives","details":"fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces to 0, keeping the loop condition permanently true.","published":"2026-07-22T06:57:13.726Z","modified":"2026-09-05T21:25:56.242918390Z","cvss":null,"epss":{"score":0.00278,"percentile":0.20304,"asOf":"2026-09-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"fflate","fixedVersion":"0.4.9"},{"ecosystem":"npm","name":"fflate","fixedVersion":"0.5.4"},{"ecosystem":"npm","name":"fflate","fixedVersion":"0.6.11"},{"ecosystem":"npm","name":"fflate","fixedVersion":"0.7.5"},{"ecosystem":"npm","name":"fflate","fixedVersion":"0.8.3"}],"fix":{"url":"https://github.com/101arrowz/fflate/commit/e6d5e6e1076892f72770ac732d83c81da9f3316e","label":"101arrowz/fflate@e6d5e6e"},"references":[{"type":"WEB","url":"https://github.com/101arrowz/fflate/blob/f7873560ad229c22c4b23b06c6a3806ffde77569/src/index.ts#L2714"},{"type":"WEB","url":"https://www.npmjs.com/package/fflate"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45820.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45820"},{"type":"WEB","url":"https://github.com/101arrowz/fflate/commit/e6d5e6e1076892f72770ac732d83c81da9f3316e"},{"type":"PACKAGE","url":"https://github.com/101arrowz/fflate"},{"type":"WEB","url":"https://github.com/101arrowz/fflate/releases/tag/v0.8.3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-05T21:25:56.242918390Z"}}