Repository navigation
Examples: Update fflate to 0.8.3 - #34737
Merged
Merged
Conversation
Fixes mrdoob#34736. fflate 0.8.2's z64e() scans a central directory entry's extra field for the ZIP64 tag with no bound on the field's declared length, so a crafted entry that sets compressed_size = 0xFFFFFFFF but never carries that tag makes unzipSync()/unzip() loop forever (CVE-2026-45820). 0.8.3 bounds the scan and raises a normal error instead. Copied from fflate's distributed ./esm/browser.js, keeping the header added in three.js, the same approach as mrdoob#27883. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Mugen87
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Fixed #34736
Description
Updates the vendored
examples/jsm/libs/fflate.module.jsfrom fflate 0.8.2 to 0.8.3, fixing CVE-2026-45820: a crafted ZIP central directory entry withcompressed_size = 0xFFFFFFFFbut no ZIP64 extra-field tag0x0001makes the oldz64e()scan run off the end of the buffer and loop forever, hangingunzipSync()/unzip(). 0.8.3 bounds that scan and raises a normal error instead.That path is reachable from
3MFLoader,AMFLoader,KMZLoader,USDLoader, andMaterialXArchive, which all callunzipSync()on archive bytes through this file.The updated code is copied from fflate's distributed
./esm/browser.js(keeping the three.js header), the same approach #27883 used for the previous fflate update. No exported function or class changed, so every module that imports from this file keeps working.I verified against both files in a child process with a timeout, using a crafted ZIP shaped as in the CVE: against the current vendored 0.8.2 it hangs past the timeout, and against the updated 0.8.3 it returns a normal "invalid zip data" error instead.
🤖 Generated with Claude Code