{"id":"CVE-2026-39904","summary":"Gophish 0.12.1 Denial of Service via Office Document Upload","details":"Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP archives and calls ioutil.ReadAll() on each contained file entry without enforcing size restrictions on uncompressed content, allowing a zip bomb payload to expand to several gigabytes in memory and cause the process to be terminated by the operating system.","aliases":["GHSA-42jc-v69j-g38f","GO-2026-6212"],"modified":"2026-09-09T18:26:44.441218643Z","published":"2026-06-22T20:11:14.670Z","related":["openSUSE-SU-2026:21761-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39904.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-770"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39904.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39904"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/gophish-denial-of-service-via-office-document-upload"},{"type":"PACKAGE","url":"https://github.com/gophish/gophish"},{"type":"EVIDENCE","url":"https://github.com/ashikmd7/GoPhish-0.12.1/blob/main/Unbounded%20Memory%20Allocation%20in%20Office%20Attachment%20Processing%20Leads%20to%20Server%20DoS/README.md"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gophish/gophish","events":[{"introduced":"0"},{"last_affected":"b1648f0759c6d57ac989157c55d8b47c40254fe6"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"0.12.1"}]}}],"versions":["v0.12.1","v0.12.0","v0.11.0","v0.10.1","v0.10.0","v0.9.0","v0.8.0","0.7.1","v0.7.0","v0.6.0","v0.5.0","v0.4.0","v0.3.0","v0.2.0","v0.1.2","v0.1.1","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-39904.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}