{"id":"GHSA-xg43-5579-qw6v","title":"adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files","summary":"adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files","severity":"medium","cvss":6.5,"cwe":["CWE-400","CWE-409"],"vendor":"adawolfa","product":"adawolfa/isdoc","ecosystem":"composer","affected":["adawolfa/isdoc >= 1.6.0, < 1.6.1","adawolfa/isdoc >= 1.5.0, < 1.5.1","adawolfa/isdoc >= 1.4.0, < 1.4.3","adawolfa/isdoc < 1.4.0"],"patched":["adawolfa/isdoc 1.6.1","adawolfa/isdoc 1.5.1","adawolfa/isdoc 1.4.3"],"published":"2026-07-15","updated":"2026-07-15","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-xg43-5579-qw6v","references":[{"url":"https://github.com/adawolfa/isdoc/security/advisories/GHSA-xg43-5579-qw6v"},{"url":"https://github.com/adawolfa/isdoc/commit/02a10123a3d5fd92950b8e4952959317c0a18952"},{"url":"https://github.com/adawolfa/isdoc/commit/935fb2aa41ceddfcf43174a61a36ec620611a105"},{"url":"https://github.com/advisories/GHSA-xg43-5579-qw6v"}],"tags":["ghsa","composer"],"ingestedAt":"2026-07-15T23:47:18.968Z","slug":"GHSA-xg43-5579-qw6v","body":"## Overview\n\n### Impact\n\n`adawolfa/isdoc` reads ISDOC invoices from ISDOCX (ZIP) archives and from PDF files with embedded ISDOC documents and supplements. Affected versions inflate ZIP entries and read embedded files **without validating their uncompressed size**, so a small crafted file can amplify into gigabytes:\n\n- **ISDOCX decompression bomb** — `getFromName()` inflates the ISDOC document and binary supplements with no size cap.\n- **`saveTo()` disk-fill** — the supplement copy loop writes inflated bytes to disk with no running byte budget, so a bomb can exhaust disk even if the central-directory size is under-reported.\n- **PDF embedded files** — an embedded file whose declared `Length` is enormous is read and digested with no upper bound.\n\nExploitation requires the application to parse an attacker-supplied `.isdocx` or `.pdf` (the typical use is generating files or parsing files from trusted vendors, so a user must be induced to process a malicious file). When that happens the process can be driven to exhaust memory or disk, causing denial of service. There is **no confidentiality or integrity impact** — availability only.\n\n### Patches\n\nFixed in **1.4.3**, **1.5.1**, **1.6.1** and **2.0.0**. The readers now:\n\n- read the uncompressed size from the ZIP central directory (`statName()`) and reject entries over a cap **before inflating** — 256 KB (`DocumentSizeLimit`) for the ISDOC document, 32 MB (`SizeLimit`) for supplements;\n- enforce a running byte budget in `saveTo()` and unlink the partial file on overflow;\n- reject PDF-embedded files whose declared `Length` exceeds 256 MB before reading or digesting them.\n\nNew exceptions `ReaderException::zipEntryTooLarge()`, `SupplementException::supplementTooLarge()` and `ReaderException::pdfSupplementTooLarge()` surface the rejection.\n\n### Unsupported versions\n\nVersions **before 1.4.0** (the 1.0–1.3 lines) are also affected and will **not** receive a fix, because they target end-of-life PHP. Users on those lines should upgrade to a maintained release — 1.4.3, 1.5.1, 1.6.1, or 2.0.0.\n\n### Workarounds\n\nNo code-level workaround exists in affected versions; upgrading is the fix. As mitigation, restrict parsing to trusted input, or enforce an external size / decompression limit (validate ZIP entry sizes, cap process memory) before handing files to the library.\n\n### Resources\n\n- Decompression-bomb fix: commit [`935fb2a`](https://github.com/adawolfa/isdoc/commit/935fb2aa41ceddfcf43174a61a36ec620611a105) (backported, released as 1.4.3 / 1.5.1 / 1.6.1) and [`02a1012`](https://github.com/adawolfa/isdoc/commit/02a10123a3d5fd92950b8e4952959317c0a18952) (master, released as 2.0.0).\n- CWE-409 (Improper Handling of Highly Compressed Data), CWE-400 (Uncontrolled Resource Consumption).\n\n## Affected packages\n\n- `adawolfa/isdoc >= 1.6.0, < 1.6.1`\n- `adawolfa/isdoc >= 1.5.0, < 1.5.1`\n- `adawolfa/isdoc >= 1.4.0, < 1.4.3`\n- `adawolfa/isdoc < 1.4.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `adawolfa/isdoc 1.6.1`\n- `adawolfa/isdoc 1.5.1`\n- `adawolfa/isdoc 1.4.3`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}