Skip to content

security: zlib inflate methods might be vulnerable to zip bombs #27253

Description

@jorangreef

From the documentation, it doesn't appear that there is any way to limit zlib's inflate methods max uncompressed size?

Without a way to limit the maximum amount of data to be uncompressed, Node's zlib inflate methods could be vulnerable to zip bombs, where a few megabytes of input could result in hundreds of megabytes of uncompressed data.

For parsers such as https://github.com/thejoshwolfe/yauzl, which parse the zip format, and which know the compressed and uncompressed sizes exactly, ahead of time, it should be possible to pass this information on to zlib's inflate methods, so that these can stop when they uncompress more than the zip container allows.

zlib's inflate methods should throw an error when more than maxUncompressedSize has been inflated.

See also: thejoshwolfe/yauzl#107

Activity

  1. added
    securityIssues and PRs related to security.
    zlibIssues and PRs related to the zlib module and its compression dependencies.
    on Apr 16, 2019
  2. addaleax commented on Apr 16, 2019

    @addaleax
    Member

    With the streaming zlib methods, it is possible to limit output size – the chunkSize option controls the output buffer size (although there currently doesn’t seem to be documentation on what it does, only that it exists), and no new input will not be consumed when no output data is being read from the stream.

    I don’t think there’s anything like this for the synchronous methods – it should be possible to add options for them as well, if you think that that helps.

  3. jorangreef commented on Apr 17, 2019

    @jorangreef
    ContributorAuthor

    Thanks @addaleax , an option for the sync methods, as well as for the asynchronous one-shot methods, e.g. zlib.inflateRaw(), would help.

  4. jasnell commented on Apr 17, 2019

    @jasnell
    Member

    We can definitely look at this for the sync methods, but in the future, for potential security issues, even if you're not entirely sure if it is a security issue, please use our hackerone account to report it more discreetly :-) https://hackerone.com/nodejs

  5. added a commit that references this issue on May 22, 2020
  6. added a commit that references this issue on Jun 9, 2020
  7. added a commit that references this issue on Jun 18, 2020
  8. added a commit that references this issue on Jun 30, 2020
  9. added a commit that references this issue on Sep 22, 2020
  10. added a commit that references this issue on Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    securityIssues and PRs related to security.zlibIssues and PRs related to the zlib module and its compression dependencies.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions