Using https://commons.apache.org/proper/commons-compress/[Apache Common Compress] 1.17 and it's new ``++InputStreamStatistics++`` can help to detect abnormally high compression ratios that may indicate a ZIP bomb during decompression as described in https://wiki.sei.cmu.edu/confluence/display/java/IDS04-J.+Safely+extract+files+from+ZipInputStream[CERT, IDS04-J.]