{"id":"CVE-2026-39904","aliases":["GHSA-42jc-v69j-g38f"],"url":"https://o3.security/vulnerability/CVE-2026-39904","summary":"Gophish 0.12.1 Denial of Service via Office Document Upload","details":"Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP archives and calls ioutil.ReadAll() on each contained file entry without enforcing size restrictions on uncompressed content, allowing a zip bomb payload to expand to several gigabytes in memory and cause the process to be terminated by the operating system.","published":"2026-06-22T20:11:14.670Z","modified":"2026-08-06T19:41:01.558161045Z","cvss":null,"epss":{"score":0.00436,"percentile":0.35876,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/gophish/gophish","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/39xxx/CVE-2026-39904.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39904"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/gophish-denial-of-service-via-office-document-upload"},{"type":"PACKAGE","url":"https://github.com/gophish/gophish"},{"type":"EVIDENCE","url":"https://github.com/ashikmd7/GoPhish-0.12.1/blob/main/Unbounded%20Memory%20Allocation%20in%20Office%20Attachment%20Processing%20Leads%20to%20Server%20DoS/README.md"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-06T19:41:01.558161045Z"}}