PT-2026-76909 · Pypi+1 · Yazl+1

·

CVE-2026-18929

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Carbone versions prior to 3.8.2 Carbone versions prior to 4.26.3 Carbone versions prior to 5.4.4
Description Denial of Service occurs when processing .docx files due to a lack of protection against zip bombs. The library utilizes yazl for zip decompression but fails to validate entry sizes. This allows an attacker to provide a malicious .docx file that decompresses to an extremely large size, leading to excessive memory consumption and crashing the application server. A zip bomb is a malicious archive file designed to crash or freeze the system reading it by expanding to an enormous size upon decompression.
Recommendations Update to version 3.8.2 Update to version 4.26.3 Update to version 5.4.4

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18929

Affected Products

Carbon
Yazl