PT-2026-51379 · Gophish · Gophish

·

CVE-2026-39904

·

Published

2026-06-22

·

Updated

2026-09-04

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Gophish versions prior to 0.12.2
Description Authenticated users with the User role can cause a denial of service by uploading a specially crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes these documents as ZIP archives and uses ioutil.ReadAll() on each file entry without enforcing size restrictions on the uncompressed content. This allows a zip bomb—a malicious archive designed to expand to an enormous size when decompressed—to consume several gigabytes of server memory, leading the operating system to terminate the process.
Recommendations Update Gophish to version 0.12.2 or later.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39904
GHSA-42JC-V69J-G38F
GO-2026-6212
OPENSUSE-SU-2026:21761-1

Affected Products

Gophish