Cyber News / Article / Vulnerability in Carbone software

Vulnerability in Carbone software
CERT Polska has received a report about vulnerability in Carbone software and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-18929: Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip decompression without validating entry sizes, allowing an attacker to supply a malicious .docx file containing a zip bomb that decompresses to a significantly larger size, causing excessive memory consumption and crashing the application server.
The issue was fixed in versions: 3.8.2, 4.26.3 and 5.4.4. The fix is available across all distribution types.
We thank MikoÅaj DÄ bek and Kamil Solecki for the responsible vulnerability report.
Related articles
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
8 days ago
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
9 days ago
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
6 days ago
You might Also like

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack

