A vulnerability, which was classified as problematic, has been found in 101arrowz fflate up to 0.4.8/0.5.3/0.6.10/0.7.4/0.8.2. Affected is the function unzipSync of the file src/index.ts of the component Zip64 Handler. The manipulation leads to infinite loop.

This vulnerability is documented as CVE-2026-45820. The attack can be initiated remotely. There is not any exploit available.