Skip to main content
Security & Malware MechanicsAdvanced Level 8 min readUpdated August 2024

What Is a ZIP Bomb? Decompression Bombs & Resource Exhaustion

A technical analysis of recursive archive bombs, non-recursive overlapping ZIP bombs, compression ratios, and parser defense mechanisms.

David Chen✓
David ChenCISSP, GCIH
Principal Systems Security Architect
Audited September 2026
Peer-Reviewed by Dr. Alistair Vance (Ph.D., CompEng)
Executive Technical Summary

A ZIP bomb (also known as a decompression bomb or archive bomb) is a maliciously crafted archive file designed to crash, hang, or exhaust the storage, memory, or CPU of an archive extractor, antivirus scanner, or cloud upload service (Denial of Service). While tiny on disk (kilobytes or megabytes), uncompressing a ZIP bomb expands into gigabytes or petabytes of data.

Formal Standards Definition

"A ZIP bomb is an algorithmic resource-exhaustion exploit that leverages high-ratio DEFLATE compression or overlapping central directory references to achieve disproportionately astronomical expansion ratios exceeding 1,000,000:1."

Cited Standards:PKWARE APPNOTECWE-409David Fifield (USENIX WOOT 2019)
Conceptual Architecture & Flow Model
Standards Model
+-------------------------------------------------------------------------+ | ZIP BOMB ANATOMY & EXPANSION PARADIGM | +-------------------------------------------------------------------------+ RECURSIVE ZIP BOMB (e.g. 42.zip): 42 KB Zip File └── Contains 16 Nested Zip Files (Layer 1) └── Each Contains 16 Zip Files (Layer 2) └── ... Nested 5 Layers Deep ... └── Expands to 4.5 Petabytes (4,500,000 Gigabytes!) NON-RECURSIVE OVERLAPPING ZIP BOMB (Fifield 2019): 46 MB Zip File ├── Central Directory references the SAME compressed kernel 281,000 times └── Expands to 4.5 Terabytes without needing nested zip recursion! │ ▼ ANYFILEX EXTRACTION DEFENSE MECHANISM: - Check declared uncompressed size in Central Directory before extraction. - Enforce hard compression ratio ceiling (Maximum 100:1). - Stream decompress with absolute memory / byte quota caps.
How the AnyFileX File Intelligence Engine Implements This

Deterministic Processing Pipeline

1Central Directory Record Inspection

Parses the End of Central Directory (EOCD) to sum the declared uncompressed size of all archive members.

parseCentralDirectoryHeaders(buffer)
2Compression Ratio Calculation

Computes Ratio = (Total Declared Uncompressed Bytes) / (Archive File Size). Flags if Ratio > 100:1.

evaluateCompressionRatio(uncompressedBytes, compressedBytes)
3Overlapping Offset Detection

Checks whether multiple file entries in the central directory point to the identical local header data offset.

detectOverlappingLocalHeaders(centralDirectoryEntries)
4Stream Extraction Quota Enforcement

Caps streaming inflation to predefined limits (e.g. 250MB max extracted) and aborts if exceeded.

streamWithByteCap(inflateStream, maxBytes=250000000)

How AnyFileX and Modern Systems Defend Against ZIP Bombs

Secure archive parsers must implement strict defenses before and during extraction: 1. Pre-Extraction Size Check: Calculate total uncompressed size from the central directory headers before allocating disk or memory. 2. Compression Ratio Limit: Discard archives exhibiting compression ratios greater than 100:1 (normal text archives rarely exceed 15:1; high-efficiency media formats are already compressed). 3. Streaming Byte Limits: Decompress data through a counting stream that throws an immediate exception if output exceeds safety quotas. 4. Overlap Detection: Verify that local header offsets increase monotonically without pointing back to previously read bytes.
CWE-409 Mitigation
Never invoke naive extraction libraries (like unzip -o or standard unzippers) on untrusted user uploads without setting hard storage quotas.
AnyFileX Technical Accuracy & Scope Boundaries

Capabilities & Operational Boundaries

AnyFileX strictly distinguishes format structural analysis and cryptographic verification from dynamic runtime malware execution.

What This Analysis Verifies
  • •Analyzes ZIP headers, compression ratios, and overlapping entry offsets.
  • •Explains the mechanics of algorithmic Denial-of-Service attacks.
  • •Details standard defensive extraction quota implementations.
Explicit Technical Limitations
  • •Does not provide tools to create or weaponize malicious archives.
Malware Analysis vs Format Inspection: A ZIP bomb is a Denial-of-Service (DoS) structural hazard, not a virus or trojan. It causes harm strictly through storage and memory saturation.
Connected AnyFileX Interactive Utilities
File Analyzer

Inspect archive headers, internal structures, and compression ratios.

Launch Tool Now
File Repair & Troubleshoot

Troubleshoot damaged or suspicious ZIP archive headers.

Launch Tool Now

Key Terminology & Standards Glossary

Decompression Bomb

A small archive file that expands to an enormous volume of data to exhaust system resources.

Compression Ratio

The ratio between uncompressed data size and compressed data size (Uncompressed / Compressed).

EOCD

End of Central Directory, the standard 22-byte trailer record at the end of a ZIP archive.

Related Technical Authority Guides

What Are Encrypted Archives? AES-256 vs ZipCrypto & Header Security
What Is File Entropy? Information Density, Compression & Encryption
How File Type Detection Works: Multi-Layered Analysis Architecture

Referenced File Format Specifications

Frequently Asked Technical Questions

Will double-clicking a ZIP bomb infect my computer with a virus?

No. A ZIP bomb does not execute malicious code or steal data. However, opening it may cause your file manager to freeze, run out of memory, or fill your hard drive to capacity until the extraction process is canceled.