What is CVE-2026-45820?
CVE-2026-45820 is a vulnerability in fflate up to version 0.8.2 that allows a denial-of-service via an infinite loop in the `unzipSync()` function when processing a crafted ZIP archive with specific malformed entries. Users should update their fflate library to the latest patched version to mitigate this issue.
Azərbaycanca: CVE-2026-45820 zəifliyi fflate kitabxanasının 0.8.2 versiyasına qədər olan versiyalarında `unzipSync()` funksiyasında xüsusi hazırlanmış ZIP faylı vasitəsilə sonsuz döngü yaradaraq denial of service (DoS) hücumuna səbəb olur. Təsirə məruz qalan sistemlərdə bu zəifliyi aradan qaldırmaq üçün kitabxananı ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
In which function was CVE-2026-45820 found?
The vulnerability was found in the `unzipSync()` function of the fflate library.
What measure should be taken to protect against this vulnerability?
The fflate library should be updated to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.