FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
CVE-2026-32630: CVE-2026-32630: Denial of Service via Data Amplification in file-type npm Package
NewsSecurity

CVE-2026-32630: CVE-2026-32630: Denial of Service via Data Amplification in file-type npm Package

via Dev.toCVE Reports2w ago

CVE-2026-32630: Denial of Service via Data Amplification in file-type npm Package Vulnerability ID: CVE-2026-32630 CVSS Score: 5.3 Published: 2026-03-13 The file-type npm package, versions 20.0.0 through 21.3.1, contains a CWE-409 (Improper Handling of Highly Compressed Data) vulnerability. The package fails to consistently apply memory allocation limits when decompressing internal ZIP file entries, allowing an unauthenticated remote attacker to trigger a Denial of Service (DoS) via a crafted, highly compressed ZIP archive. TL;DR file-type versions 20.0.0 to 21.3.1 are vulnerable to a ZIP bomb attack. Bypassed decompression limits for known-size inputs lead to massive memory allocation when processing crafted ZIP entries, resulting in an Out-of-Memory (OOM) process crash. ⚠️ Exploit Status: POC Technical Details CVE ID : CVE-2026-32630 CVSS v3.1 : 5.3 Attack Vector : Network Impact : Denial of Service (OOM) CWE ID : CWE-409 CISA KEV Status : Not Listed Affected Systems Node.js server a

Continue reading on Dev.to

Opens in a new tab

Read Full Article
9 views

Related Articles

These car gadgets are worth every penny
News

These car gadgets are worth every penny

ZDNet • 11h ago

These Are the 4 Artemis II Astronauts Leading the Historic Return to the Moon
News

These Are the 4 Artemis II Astronauts Leading the Historic Return to the Moon

Wired • 11h ago

Taylor Lorenz’s Screen Time Is Almost 17 Hours a Day
News

Taylor Lorenz’s Screen Time Is Almost 17 Hours a Day

Wired • 11h ago

RSpec Best Practices in 2026: Factory Bot + VCR Cassettes
News

RSpec Best Practices in 2026: Factory Bot + VCR Cassettes

Medium Programming • 11h ago

The $380K Outage — Complete Timeline From Hell (2:14 AM to 4:02 AM)
News

The $380K Outage — Complete Timeline From Hell (2:14 AM to 4:02 AM)

Medium Programming • 12h ago

Discover More Articles