CERT Polska disclosed CVE-2026-18929, a denial-of-service vulnerability in Carbone caused by improper handling of highly compressed data inside .docx files. The flaw lets a malicious document act as a ZIP bomb, expanding massively in memory and crashing the application server. The issue was described as a data amplification problem tied to Carbone's processing of compressed content.
The vulnerability affects all Carbone versions before 3.8.2 and stems from the software's use of yazl for ZIP decompression without validating entry sizes. Fixes were released in versions 3.8.2, 4.26.3, and 5.4.4. CERT Polska coordinated disclosure of the issue, and researchers Mikołaj Dąbek and Kamil Solecki were credited with responsibly reporting the bug.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CERT Polska published CVE-2026-18929, a denial-of-service vulnerability in Carbone caused by improper handling of highly compressed data in .docx files. The flaw affects all Carbone versions before 3.8.2 and can let a malicious zip bomb consume excessive memory and crash the application server.
The vulnerability was fixed in Carbone versions 3.8.2, 4.26.3, and 5.4.4, with fixes available across all distribution types. These releases address the zip-bomb-related denial-of-service issue in .docx processing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.