{"id":"CVE-2026-32630","summary":"file-type affected by ZIP Decompression Bomb DoS via [Content_Types].xml entry","details":"file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excessive memory growth during type detection in file-type when using fileTypeFromBuffer(), fileTypeFromBlob(), or fileTypeFromFile(). The ZIP inflate output limit is enforced for stream-based detection, but not for known-size inputs. As a result, a small compressed ZIP can cause file-type to inflate and process a much larger payload while probing ZIP-based formats such as OOXML. This vulnerability is fixed in 21.3.2.","aliases":["GHSA-j47w-4g3g-c36v"],"modified":"2026-08-12T03:51:15.885263395Z","published":"2026-03-13T20:54:16.960Z","related":["CGA-h5g7-56x8-w3x5"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32630.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-409"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32630.json"},{"type":"ADVISORY","url":"https://github.com/sindresorhus/file-type/security/advisories/GHSA-j47w-4g3g-c36v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32630"},{"type":"FIX","url":"https://github.com/sindresorhus/file-type/commit/399b0f156063f5aeb1c124a7fd61028f3ea7c124"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sindresorhus/file-type","events":[{"introduced":"3945d7fa20b05d03fd0100578ca5332b7acfa467"},{"fixed":"e18028c3cc19441477c3459991fee9770d88c218"},{"fixed":"399b0f156063f5aeb1c124a7fd61028f3ea7c124"}],"database_specific":{"cpe":"cpe:2.3:a:sindresorhus:file-type:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"20.0.0"},{"fixed":"21.3.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v21.3.1","v21.3.0","v21.2.0","v21.1.1","v21.1.0","v21.0.0","v20.5.0","v20.4.1","v20.4.0","v20.3.0","v20.2.0","v20.1.0","v20.0.1","v20.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32630.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}