CVE-2026-45820
Description
A flaw was found in fflate. A remote attacker could exploit this vulnerability by providing a specially crafted ZIP archive. This archive, when processed, can lead to an infinite loop during decompression, causing a Denial of Service (DoS) condition. This occurs because a malformed central directory entry in the ZIP archive causes out-of-bounds reads, which keeps a processing loop permanently active.
Statement
This CVE describes a denial-of-service flaw in the fflate JavaScript compression library. Parsing a maliciously crafted ZIP archive via unzipSync()/unzip() triggers an infinite loop in the ZIP64 central-directory parser (z64e): a central directory entry declaring the ZIP64 size sentinel (0xFFFFFFFF) but omitting the required ZIP64 extra field causes out-of-bounds reads that keep the loop condition permanently true, consuming CPU indefinitely. Only fflate's ZIP-extraction APIs are affected; its gzip/deflate/zip-creation paths are not.
Red Hat products bundle fflate almost exclusively within web-frontend assets. Each affected component was assessed individually. Components that reach fflate only through compression-only consumers (posthog-js gzip telemetry, jsPDF zlib) never invoke the vulnerable unzipSync/z64e path and are marked not affected (vulnerable code not in the execute path). Components that bundle fflate in the vulnerable version range (through 0.8.2) where the ZIP-extraction path could not be positively excluded are marked affected. Where the vulnerable path is reachable only from client-side browser code processing same-origin assets, practical impact is limited to a self-inflicted denial of service within the user's own browser session rather than a service-level outage.
Mitigation
There is no available mitigation for this flaw other than updating the bundled fflate library to a fixed version (0.8.3 or later). Where the application controls the input, avoid passing untrusted ZIP archives to fflate's unzip()/unzipSync() APIs.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7.5 | 7.5 | N/A |
| Attack Vector | Network | Network | N/A |
| Attack Complexity | Low | Low | N/A |
| Privileges Required | None | None | N/A |
| User Interaction | None | None | N/A |
| Scope | Unchanged | Unchanged | N/A |
| Confidentiality | None | None | N/A |
| Integrity Impact | None | None | N/A |
| Availability Impact | High | High | N/A |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Amplification
An infinite loop will cause unexpected consumption of resources, such as CPU cycles or memory. The software's operation may slow down, or cause a long time to respond.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.