CVE-2026-65827: Docmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial of service

Published Sep 24, 2026
·
Updated

Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated workspace member with edit rights to a space can upload an archive to the page-import feature whose ZIP extraction routine does not limit total uncompressed size, per-entry size, or entry count. The extractor writes entries to the server temp directory and automatically extracts one nested ZIP, allowing an outer upload within the default 200 MB limit to expand by multiple GB. The resulting disk exhaustion can crash the import worker and degrade or take down the instance for all tenants. This issue is fixed in version 0.95.0.

Affected Software

1 affected component
docmost docmost>=0.21.0<0.95.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Docmost to a version that resolves this vulnerability.

    Fixed in 0.95.0

Event History

Sep 24, 2026
CVE Published
via MITRE·06:28 PM
Data Sourced
via MITRE·06:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can trigger the issue?

Any authenticated workspace member who has edit rights to a space can exploit it. No administrative privileges or user interaction are required.

2

Are deployments using the default upload limit still exposed?

Yes. An archive within the default 200 MB upload limit can expand to multiple GB during extraction, including through one automatically extracted nested ZIP.

3

What systems are affected?

Docmost versions from 0.21.0 until 0.95.0 are affected. Version 0.95.0 fixes the issue.

4

What is the operational impact of exploitation?

Extracted archive contents are written to the server temporary directory without limits on total uncompressed size, per-entry size, or entry count. Disk exhaustion can crash the import worker and degrade or take down the instance for all tenants.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203