mediumCVSS 6.5Vulnerability

GHSA-xg43-5579-qw6v

### Impact `adawolfa/isdoc` reads ISDOC invoices from ISDOCX (ZIP) archives and from PDF files with embedded ISDOC documents and supplements. Affected versions inflate ZIP entries and read embedded files **without validating their uncompressed size**, so a small crafted file can amplify into gigabytes: - **ISDOCX decompression bomb** — `getFromName()` inflates the ISDOC document and binary supplements with no size cap. - **`saveTo()` disk-fill** — the supplement copy loop writes inflated bytes to disk with no running byte budget, so a bomb can exhaust disk even if the central-directory size is under-reported. - **PDF embedded files** — an embedded file whose declared `Length` is enormous is read and digested with no upper bound. Exploitation requires the application to parse an attacker-supplied `.isdocx` or `.pdf` (the typical use is generating files or parsing files from trusted vendors, so a user must be induced to process a malicious file). When that happens the process can be driven to exhaust memory or disk, causing denial of service. There is **no confidentiality or integrity impact** — availability only. ### Patches Fixed in **1.4.3**, **1.5.1**, **1.6.1** and **2.0.0**. The readers now: - read the uncompressed size from the ZIP central directory (`statName()`) and reject entries over a cap **before inflating** — 256 KB (`DocumentSizeLimit`) for the ISDOC document, 32 MB (`SizeLimit`) for supplements; - enforce a running byte budget in `saveTo()` and unlink the partial file on overflow; - reject PDF-embedded files whose declared `Length` exceeds 256 MB before reading or digesting them. New exceptions `ReaderException::zipEntryTooLarge()`, `SupplementException::supplementTooLarge()` and `ReaderException::pdfSupplementTooLarge()` surface the rejection. ### Unsupported versions Versions **before 1.4.0** (the 1.0–1.3 lines) are also affected and will **not** receive a fix, because they target end-of-life PHP. Users on those lines should upgrade to a mai

Properties

ghsa_id
GHSA-xg43-5579-qw6v
severity
medium
summary
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files
cvss_score
6.5
cve_id
GHSA-xg43-5579-qw6v
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-07-15T23:30:55Z
source_url
https://github.com/advisories/GHSA-xg43-5579-qw6v
ghsa_updated
2026-07-15T23:30:57Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]composer/adawolfa/isdoc

AFFECTS (1)

[Software]composer/adawolfa/isdoc

HAS_WEAKNESS (2)

[Weakness]Uncontrolled Resource Consumption
[Weakness]Improper Handling of Highly Compressed Data (Data Amplification)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-xg43-5579-qw6v (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal