Search/CVE-2026-18929
CVE

CVE-2026-18929

Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip decompression without validating entry sizes, allowing an attacker to supply a malicious .docx file containing a zip bomb that decompresses to a significantly larger size, causing excessive memory consumption and crashing the application server. The issue was fixed in versions: 3.8.2, 4.26.3 and 5.4.4. The fix is available across all distribution types.

CVSS v3.1
EPSS
0.43%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 20, 2026Aug 26, 2026
0.09pp
0.52% → 0.43% over 2 tracked changes
Connections
1 relationships
Timeline
disclosure → media coverage
Aug 18, 2026
Disclosure — published as a CVE record.