What is CVE-2026-18929?
Carbone library is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. An attacker can supply a malicious .docx file containing a highly compressed archive that exhausts memory or disk resources during decompression. Affected users should upgrade Carbone to the latest patched version.
Azərbaycanca: Carbone kitabxanası .docx fayllarını emal edərkən zip bombalarına qarşı qorunma olmaması səbəbindən xidmət rəddi (DoS) zəifliyinə məruz qalır. Bu, təcavüzkara şişirdilmiş ölçülü zip arxivi olan zərərli .docx faylı təqdim edərək yaddaş və ya disk resurslarını tükəndirməyə imkan verir. Təsirə məruz qalan sistemlərdə Carbone-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
What is the impact of CVE-2026-18929 in the Carbone library?
It causes Denial of Service (DoS) by exhausting memory or disk resources when processing malicious .docx files that contain zip bombs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.