Vulnerability Description
Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email template attachment. The ApplyTemplate() function in models/attachment.go processes Office documents as ZIP archives and calls ioutil.ReadAll() on each contained file entry without enforcing size restrictions on uncompressed content, allowing a zip bomb payload to expand to several gigabytes in memory and cause the process to be terminated by the operating system.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/ashikmd7/GoPhish-0.12.1/blob/main/Unbounded%20Memory%20Alloca
- https://www.vulncheck.com/advisories/gophish-denial-of-service-via-office-docume
FAQ
What is CVE-2026-39904?
CVE-2026-39904 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email templat...
How severe is CVE-2026-39904?
CVE-2026-39904 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-39904?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.