# Carbone Patches Zip Bomb DoS Flaw

Published: 2026-08-18 · Severity: routine
Canonical: https://vorant.io/reports/ae2f2cd7-8f6f-581e-91fd-6c3e14bb27b5/carbone-patches-zip-bomb-dos-flaw

> A vulnerability in Carbone's .docx processing lets attackers crash servers via unvalidated zip bomb decompression, now patched.

CERT Polska coordinated disclosure of CVE-2026-18929, a Denial of Service vulnerability in the Carbone document generation software. The flaw stems from Carbone's use of the yazl library for zip decompression when processing .docx files, without validating entry sizes before decompression. An attacker can craft a malicious .docx file containing a zip bomb that expands to a disproportionately large size upon processing, exhausting server memory and crashing the application.

The vulnerability was responsibly reported by researchers Mikołaj Dąbek and Kamil Solecki through CERT Polska's coordinated vulnerability disclosure process. Carbone has released fixes across all distribution types in versions 3.8.2, 4.26.3, and 5.4.4. There is no indication of active exploitation in the wild; this is a proactive disclosure and patch advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-18929

Source reporting: https://cert.pl/en/posts/2026/08/CVE-2026-18929

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ae2f2cd7-8f6f-581e-91fd-6c3e14bb27b5/carbone-patches-zip-bomb-dos-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
