{
  "id": 12717341,
  "title": "Zip Slip and decompression bombs in Java: how to extract safely",
  "url": "https://urgent.news/2026/10/07/zip-slip-and-decompression-bombs-in-java-how-to-extract-safely",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T21:23:02.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/austek/zip-slip-and-decompression-bombs-in-java-how-to-extract-safely-54hl"
  },
  "original_language": "en",
  "account": "Extracting untrusted archives poses two security risks: Zip Slip and decompression bombs. Zip Slip allows attackers to write files outside the intended directory using crafted entry names like \"../../pwned.txt\". Decompression bombs trick the system into decompressing massive amounts of data from small files, filling up disk space. The Java Development Kit (JDK) can be used to extract archives safely, with the Compress4J library offering additional protections.\n\nTo prevent Zip Slip, normalize the resolved path and reject any that leave the output directory. This solution works for the pure-JDK Compress4J, and Compress4J provides built-in normalization for every format. However, symlinks require additional checks. Compress4J rejects absolute and escaping symlink targets by default, which prevents attackers from creating symlinks to sensitive directories like \"/etc\".\n\nDecompression bombs exploit the compression algorithm's ability to compress runs of identical bytes by a factor of 1000:1. Attackers can create small files that, when decompressed, consume significant disk space. Compress4J's default extraction limits prevent such issues with a ratio of 100 and a maximum size of 1 MiB. For highly repetitive data, like log archives, larger limits may be necessary. The UnsafeInputException and LimitExceededException can be caught to handle both Zip Slip and decompression bomb attacks.",
  "summary": "Extracting an archive you did not create is a security boundary. Two attacks cross it with a few lines of crafted input: Zip Slip writes outside the target directory, and a decompression bomb fills your disk from a tiny file. This post reproduces both against the JDK and shows the fix. Every snippet ran against Compress4J 5.0.0 on Java 21. Zip Slip Zip Slip, disclosed by Snyk in 2018, abuses…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}