Decompression Bomb Detection
SkillDocs & knowledgeDetect decompression bomb vulnerabilities where compressed input can expand to exhaust memory, targeting buffer-based decompression without size limits.
Use Decompression Bomb Detection in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Decompression Bomb Detection and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Decompression Bomb Detection skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by byamb4/find-cve-agent in skills/decompression-bomb/SKILL.md and read by Ahel’s review.
When to Use
Audit archive/compression libraries, file upload handlers, content-encoding processors, and any package that decompresses user-supplied data.
Key Insight
Buffer-based decompression is vulnerable: the entire decompressed output is loaded into memory at once. A 1KB compressed payload can expand to 1GB+.
Stream-based MAY have backpressure: but only if the consumer applies it. Many stream implementations still buffer the entire output.
Process
Step 1: Find Decompression Sinks
# JavaScript
grep -rn "zlib\.gunzip\|zlib\.inflate\|zlib\.unzip\|zlib\.brotli" .
grep -rn "gunzipSync\|inflateSync\|unzipSync\|brotliDecompress" .
grep -rn "pako\|fflate\|lz-string\|snappy" .
grep -rn "decompress\|decompressSync\|uncompress" .
# Python
grep -rn "zlib\.decompress\|gzip\.decompress\|bz2\.decompress" .
grep -rn "lzma\.decompress\|snappy\.decompress" .
# Go
grep -rn "gzip\.NewReader\|zlib\.NewReader\|flate\.NewReader" .
grep -rn "compress/gzip\|compress/zlib\|compress/flate" .
Step 2: Check for Size Limits
grep -rn "maxSize\|maxOutput\|maxLength\|MAX_SIZE\|outputLimit\|sizeLimit" .
grep -rn "ratio\|compressionRatio\|maxRatio" .
Step 3: Check Buffer vs Stream
Buffer-based (VULNERABLE):
zlib.gunzipSync(input) // Entire output in memory
zlib.gunzip(input, (err, result) => {}) // Callback with full buffer
Stream-based (CHECK):
input.pipe(zlib.createGunzip()).pipe(output) // Streaming, may have backpressure
Even stream-based can be vulnerable if:
- Output is collected into a buffer:
const chunks = []; stream.on('data', c => chunks.push(c)) - No backpressure is applied
- Consumer reads faster than it can process
Step 4: Verify Exploitability
- Can the attacker supply compressed data? (file upload, HTTP content-encoding, archive processing)
- Is there an input size limit that would prevent the bomb?
- Is there a decompressed size limit?
- Is the process memory-limited?
CVSS Guidance
- Unauthenticated OOM crash: HIGH 7.5
- Authenticated OOM crash: MEDIUM 6.5
- Stream-based with memory growth: MEDIUM 5.3
- With input size limits that bound expansion: may not be exploitable
References
- Sinks -- Decompression sinks by language
- False Positive Indicators
- PoC Skeleton
Signals
- GitHub stars
- 53
- Forks
- 10
- Last commit
- Mar 2026
Advanced
- Item type
- skill
- Key
decompression-bomb- Source
- github.com/byamb4/find-cve-agent
github.com/byamb4/find-cve-agent
Related picks
Skill · stbenjam
The pick for Dependenciesauditing-python-dependencies
Skill · jeremylongshore
The pick for Dependencieschecking-owasp-compliance
Skill · jeremylongshore
The pick for Web (OWASP)owasp-security
Skill · davila7
The pick for Web (OWASP)handoff
Skill · mattpocock
More in Docs & knowledgecanvas-design
Skill · anthropics
More in Docs & knowledge