Sceawere

Vulnerability Detail

CVE-2026-108750UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenDocMan Decompression Bomb Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
4h ago
Vendor
OpenDocMan
Product
OpenDocMan
Attack Type
Improper Handling of Highly Compressed Data (Data Amplification)
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

OpenDocMan 2.4.0 through 2.10.0 contains a decompression bomb vulnerability that allows authenticated users to exhaust PHP memory by uploading crafted office documents. Attackers can upload a small ODT, DOCX, or XLSX file whose XML entries decompress to hundreds of megabytes, crashing PHP workers and degrading availability.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T13:17:19.810Z",
  "pubdate": "2026-10-11T13:17:19.810Z",
  "executiveSummary": "OpenDocMan versions 2.4.0 through 2.10.0 are susceptible to a decompression bomb vulnerability, classified as a resource exhaustion flaw.\nThis vulnerability allows authenticated users to trigger a denial-of-service (DoS) condition by uploading specifically crafted office documents (ODT, DOCX, XLSX).\nThe attack leverages the underlying compression mechanisms used for these file formats, which are essentially ZIP archives containing XML data structures.\nBy manipulating the compression ratio, an attacker can submit a compact file that expands to hundreds of megabytes during server-side processing.\nThe primary impact is the exhaustion of PHP memory limits, resulting in the termination of PHP worker processes and overall service unavailability.\nExploitation requires authenticated access to the application, posing a significant risk to environment stability and availability.\nThis vulnerability highlights insufficient input validation regarding file size expansion limits during the document processing phase of the application.",
  "technicalDetails": "The vulnerability resides in the document processing engine of OpenDocMan versions 2.4.0 through 2.10.0, which performs server-side parsing and decompression of uploaded office documents.\nOffice document formats such as ODT, DOCX, and XLSX are based on the Office Open XML standard, which packages data within ZIP containers.\nThe application's parsing logic fails to enforce constraints on the decompressed size of these archives before attempting to load them into memory.\nAn attacker exploits this by creating a maliciously crafted ZIP file that utilizes high compression ratios, a technique commonly referred to as a 'decompression bomb' or 'ZIP bomb'.\nThe attack flow begins when an authenticated user uploads the malicious file via the OpenDocMan file upload interface. Upon receipt, the application initiates a routine to inspect or process the document contents.\nDuring this inspection, the server-side PHP worker attempts to decompress the XML payloads contained within the ZIP structure. Because the application does not validate the expansion ratio or the final decompressed size, the file content expands significantly beyond the available memory allocated to the PHP worker.\nThe rapid consumption of system memory triggers an out-of-memory (OOM) error or causes the PHP worker process to crash, effectively resulting in a denial-of-service condition.\nBecause OpenDocMan relies on persistent PHP worker pools (such as FPM), repeated triggers of this exploit can lead to the exhaustion of the entire worker pool, rendering the application entirely unresponsive to legitimate user traffic.\nThis vulnerability is particularly impactful because it bypasses standard file size upload limits, which typically only measure the size of the compressed file stored on disk rather than the resource footprint generated during the extraction process.\nThe vulnerability requires the attacker to possess an authenticated account, but does not necessitate high-level administrative privileges, making it a viable vector for any user with file upload permissions."
}
CVE-2026-108750: OpenDocMan Decompression Bomb Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere