{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":[]},"type":"markdown"},"seo":{"title":"Decompression Vulnerabilities","siteUrl":"https://docs.hiddenlayer.ai"},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"decompression-vulnerabilities","__idx":0},"children":["Decompression Vulnerabilities"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"detection-summary","__idx":1},"children":["Detection Summary"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The model uses compression formats in a way that may trigger denial of service or data leakage."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"security-impact","__idx":2},"children":["Security Impact"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Exploitation of decompression vulnerabilities can exhaust system resources, leading to denial of service, and can also be used to overwrite files, enabling arbitrary code execution."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"false-positive-considerations","__idx":3},"children":["False Positive Considerations"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Large legitimate models may trigger alerts due to size or complexity."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"recommended-remediation","__idx":4},"children":["Recommended Remediation"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Do not load or deploy the affected model. It should be isolated from production systems."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Engage the team responsible for the development and deployment of the model, letting them know the nature of the detection."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["The contents of the archive file should be examined in a safe manner so the implications of loading it can be fully understood. If necessary, have a member of the security team work with the application team to do this."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["If the contents of the archive file cannot be confirmed as legitimate, the model should be discarded."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["If this model has already been loaded, have your security team examine the files associated with the detection in order to understand the impact and determine the best way to handle the incident based on existing procedures and policy."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["If a file has been overwritten, remove the model from the production pipeline, ensuring the business and operational impact of removal is mitigated."]}]}]},"headings":[{"value":"Decompression Vulnerabilities","id":"decompression-vulnerabilities","depth":1},{"value":"Detection Summary","id":"detection-summary","depth":2},{"value":"Security Impact","id":"security-impact","depth":2},{"value":"False Positive Considerations","id":"false-positive-considerations","depth":2},{"value":"Recommended Remediation","id":"recommended-remediation","depth":2}],"frontmatter":{"seo":{"title":"Decompression Vulnerabilities"}},"lastModified":"2026-05-26T18:25:46.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/docs/products/supply-chain/remediation-guide/decompression_vulnerabilities","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}