CVE-2026-108750
Description
OpenDocMan 2.4.0 through 2.10.0 contains a decompression bomb vulnerability that allows authenticated users to exhaust PHP memory by uploading crafted office documents. Attackers can upload a small ODT, DOCX, or XLSX file whose XML entries decompress to hundreds of megabytes, crashing PHP workers and degrading availability.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/opendocman/opendocman
- https://github.com/opendocman/opendocman/blob/641f0a6f8eeba902e309978ec04291c44d3cd1c5/application/models/Document.class.php#L67-L75
- https://github.com/opendocman/opendocman/blob/641f0a6f8eeba902e309978ec04291c44d3cd1c5/application/models/TextExtractors/OdtExtractor.class.php#L10-L25
- https://hackmd.io/@haind03/opendocman-office-document-decompression-dos
- https://www.vulncheck.com/advisories/opendocman-2.4.0-through-2.10.0-decompression-bomb-dos-via-upload-text-extraction
CWEs
CWE-409
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.