CERT Polska disclosed CVE-2026-18929, a denial-of-service vulnerability in Carbone that allows a specially crafted .docx file to exhaust server memory and crash the application. The issue stems from improper handling of highly compressed data during ZIP processing: Carbone uses yazl for decompression without validating archive entry sizes, enabling a malicious document to expand massively in memory when processed.
The flaw affects all Carbone versions before 3.8.2 and has been fixed in versions 3.8.2, 4.26.3, and 5.4.4. The weakness aligns with CWE-409 Improper Handling of Highly Compressed Data (Data Amplification), commonly associated with zip-bomb style attacks. CERT Polska coordinated disclosure, and Mikołaj Dąbek and Kamil Solecki were credited with responsibly reporting the vulnerability.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On 18 August 2026, CVE-2026-18929 was published for a Carbone denial-of-service vulnerability involving malicious .docx zip bombs that can trigger excessive memory consumption and crash the application server. CERT Polska says it received the report and coordinated disclosure, and credits Mikołaj Dąbek and Kamil Solecki with responsibly reporting the issue.
Carbone released fixes for a denial-of-service vulnerability caused by improper handling of highly compressed data in .docx files. The issue affects all versions before 3.8.2, and the vendor states it was fixed in versions 3.8.2, 4.26.3, and 5.4.4 across all distribution types.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.