VORANT. Threat Intelligence Sign in Get the full feed

Carbone Patches Zip Bomb DoS Flaw

routine vulnerability

A vulnerability in Carbone's .docx processing lets attackers crash servers via unvalidated zip bomb decompression, now patched.

CERT Polska coordinated disclosure of CVE-2026-18929, a Denial of Service vulnerability in the Carbone document generation software. The flaw stems from Carbone's use of the yazl library for zip decompression when processing .docx files, without validating entry sizes before decompression. An attacker can craft a malicious .docx file containing a zip bomb that expands to a disproportionately large size upon processing, exhausting server memory and crashing the application.

The vulnerability was responsibly reported by researchers Mikołaj Dąbek and Kamil Solecki through CERT Polska's coordinated vulnerability disclosure process. Carbone has released fixes across all distribution types in versions 3.8.2, 4.26.3, and 5.4.4. There is no indication of active exploitation in the wild; this is a proactive disclosure and patch advisory.

Mentioned in this report

Vulnerabilities CVE-2026-18929

Source reporting: https://cert.pl/en/posts/2026/08/CVE-2026-18929

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free