Denial of Service Vulnerability in Carbone Document Processing by Carbone.io
CVE-2026-18929

6.9MEDIUM

Key Information:

Vendor

Carbone

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-18929?

Carbone is susceptible to denial of service attacks due to an insufficient defense against zip bombs when handling .docx files. The library utilizes yazl for zip decompression but fails to validate file entry sizes. This oversight enables attackers to craft malicious .docx files that decompress into excessively large sizes, leading to significant memory consumption and potential application server crashes. Users are advised to upgrade to the patched versions to mitigate this risk.

Affected Version(s)

Carbone 0 < 3.8.2

Carbone 0 < 4.26.3

Carbone 0 < 5.4.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mikołaj Dąbek
Kamil Solecki
.