Skip to content

Examples: Update fflate to 0.8.3 - #34737

Merged
Mugen87 merged 1 commit into
mrdoob:devfrom
brennanmceachran:fflate-0.8.3
Oct 2, 2026
Merged

Mugen87 merged 1 commit into
mrdoob:devfrom
brennanmceachran:fflate-0.8.3

Conversation

@brennanmceachran

@brennanmceachran brennanmceachran commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Fixed #34736

Description

Updates the vendored examples/jsm/libs/fflate.module.js from fflate 0.8.2 to 0.8.3, fixing CVE-2026-45820: a crafted ZIP central directory entry with compressed_size = 0xFFFFFFFF but no ZIP64 extra-field tag 0x0001 makes the old z64e() scan run off the end of the buffer and loop forever, hanging unzipSync()/unzip(). 0.8.3 bounds that scan and raises a normal error instead.

That path is reachable from 3MFLoader, AMFLoader, KMZLoader, USDLoader, and MaterialXArchive, which all call unzipSync() on archive bytes through this file.

The updated code is copied from fflate's distributed ./esm/browser.js (keeping the three.js header), the same approach #27883 used for the previous fflate update. No exported function or class changed, so every module that imports from this file keeps working.

I verified against both files in a child process with a timeout, using a crafted ZIP shaped as in the CVE: against the current vendored 0.8.2 it hangs past the timeout, and against the updated 0.8.3 it returns a normal "invalid zip data" error instead.

🤖 Generated with Claude Code

Fixes mrdoob#34736. fflate 0.8.2's z64e() scans a central directory entry's
extra field for the ZIP64 tag with no bound on the field's declared
length, so a crafted entry that sets compressed_size = 0xFFFFFFFF but
never carries that tag makes unzipSync()/unzip() loop forever
(CVE-2026-45820). 0.8.3 bounds the scan and raises a normal error
instead.

Copied from fflate's distributed ./esm/browser.js, keeping the header
added in three.js, the same approach as mrdoob#27883.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Mugen87
Mugen87 merged commit ad43b02 into mrdoob:dev Oct 2, 2026
9 checks passed
@Mugen87 Mugen87 added this to the r187 milestone Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vendored fflate 0.8.2 can hang forever in unzipSync() (CVE-2026-45820)

2 participants