What Is a ZIP Bomb? Decompression Bombs & Resource Exhaustion
A technical analysis of recursive archive bombs, non-recursive overlapping ZIP bombs, compression ratios, and parser defense mechanisms.
A ZIP bomb (also known as a decompression bomb or archive bomb) is a maliciously crafted archive file designed to crash, hang, or exhaust the storage, memory, or CPU of an archive extractor, antivirus scanner, or cloud upload service (Denial of Service). While tiny on disk (kilobytes or megabytes), uncompressing a ZIP bomb expands into gigabytes or petabytes of data.
"A ZIP bomb is an algorithmic resource-exhaustion exploit that leverages high-ratio DEFLATE compression or overlapping central directory references to achieve disproportionately astronomical expansion ratios exceeding 1,000,000:1."
Deterministic Processing Pipeline
Parses the End of Central Directory (EOCD) to sum the declared uncompressed size of all archive members.
parseCentralDirectoryHeaders(buffer)Computes Ratio = (Total Declared Uncompressed Bytes) / (Archive File Size). Flags if Ratio > 100:1.
evaluateCompressionRatio(uncompressedBytes, compressedBytes)Checks whether multiple file entries in the central directory point to the identical local header data offset.
detectOverlappingLocalHeaders(centralDirectoryEntries)Caps streaming inflation to predefined limits (e.g. 250MB max extracted) and aborts if exceeded.
streamWithByteCap(inflateStream, maxBytes=250000000)How AnyFileX and Modern Systems Defend Against ZIP Bombs
Capabilities & Operational Boundaries
AnyFileX strictly distinguishes format structural analysis and cryptographic verification from dynamic runtime malware execution.
- •Analyzes ZIP headers, compression ratios, and overlapping entry offsets.
- •Explains the mechanics of algorithmic Denial-of-Service attacks.
- •Details standard defensive extraction quota implementations.
- •Does not provide tools to create or weaponize malicious archives.
Inspect archive headers, internal structures, and compression ratios.
Troubleshoot damaged or suspicious ZIP archive headers.
Key Terminology & Standards Glossary
A small archive file that expands to an enormous volume of data to exhaust system resources.
The ratio between uncompressed data size and compressed data size (Uncompressed / Compressed).
End of Central Directory, the standard 22-byte trailer record at the end of a ZIP archive.
Related Technical Authority Guides
Referenced File Format Specifications
Frequently Asked Technical Questions
Will double-clicking a ZIP bomb infect my computer with a virus?
No. A ZIP bomb does not execute malicious code or steal data. However, opening it may cause your file manager to freeze, run out of memory, or fill your hard drive to capacity until the extraction process is canceled.