Denial of Service Vulnerability in Carbone Document Processing by Carbone.io
CVE-2026-18929
6.9MEDIUM
What is CVE-2026-18929?
Carbone is susceptible to denial of service attacks due to an insufficient defense against zip bombs when handling .docx files. The library utilizes yazl for zip decompression but fails to validate file entry sizes. This oversight enables attackers to craft malicious .docx files that decompress into excessively large sizes, leading to significant memory consumption and potential application server crashes. Users are advised to upgrade to the patched versions to mitigate this risk.
Affected Version(s)
Carbone 0 < 3.8.2
Carbone 0 < 4.26.3
Carbone 0 < 5.4.4
