CVE-2026-18929
Resource Exhaustion in Carbone
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip decompression without validating entry sizes, allowing an attacker to supply a malicious .docx file containing a zip bomb that decompresses to a significantly larger size, causing excessive memory consumption and crashing the application server. The issue was fixed in versions: 3.8.2, 4.26.3 and 5.4.4. The fix is available across all distribution types.
| CWE | CWE-409 |
| Vendor | carbone |
| Product | carbone |
| Published | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for carbone carbone
Be the first to know when new unknown vulnerabilities affecting carbone carbone are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Carbone / Carbone
0 < 3.8.2 0 < 4.26.3 0 < 5.4.4
References
Credits
Mikołaj Dąbek Kamil Solecki