CVE-2026-65827

Source
https://cve.org/CVERecord?id=CVE-2026-65827
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65827.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-65827
Aliases
  • GHSA-frjw-66gr-799m
Published
2026-09-24T18:28:36Z
Modified
2026-09-26T03:46:52Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Docmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial of service
Details

Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated workspace member with edit rights to a space can upload an archive to the page-import feature whose ZIP extraction routine does not limit total uncompressed size, per-entry size, or entry count. The extractor writes entries to the server temp directory and automatically extracts one nested ZIP, allowing an outer upload within the default 200 MB limit to expand by multiple GB. The resulting disk exhaustion can crash the import worker and degrade or take down the instance for all tenants. This issue is fixed in version 0.95.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-400",
        "CWE-409",
        "CWE-770"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65827.json"
}
References

Affected packages

Git / github.com/docmost/docmost

Affected ranges

Type
GIT
Repo
https://github.com/docmost/docmost
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.21.0"
        },
        {
            "fixed":  "0.95.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.21.0
v0.22.0
v0.22.1
v0.22.2
v0.23.0
v0.23.1
v0.23.2
v0.24.0
v0.24.1
v0.25.0
v0.25.0-beta.1
v0.25.1
v0.25.2
v0.25.3
v0.70.0
v0.70.1
v0.70.2
v0.70.3
v0.71.0
v0.71.1
v0.80.1
v0.90.0
v0.90.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65827.json"