🔐 CVE Alert

CVE-2026-18929

UNKNOWN 0.0

Resource Exhaustion in Carbone

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip decompression without validating entry sizes, allowing an attacker to supply a malicious .docx file containing a zip bomb that decompresses to a significantly larger size, causing excessive memory consumption and crashing the application server. The issue was fixed in versions: 3.8.2, 4.26.3 and 5.4.4.  The fix is available across all distribution types.

CWE CWE-409
Vendor carbone
Product carbone
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for carbone carbone

Be the first to know when new unknown vulnerabilities affecting carbone carbone are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Carbone / Carbone
0 < 3.8.2 0 < 4.26.3 0 < 5.4.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/08/CVE-2026-18929 carbone.io: https://carbone.io/ github.com: https://github.com/carboneio/carbone/commit/eb9b4cff992cc1cb1a319d7fc0cbd09160dc214e

Credits

Mikołaj Dąbek Kamil Solecki