7.3
CVE-2026-106164
- EPSS 0.19%
- Veröffentlicht 07.10.2026 18:02:32
- Zuletzt bearbeitet 08.10.2026 20:49:23
- Erkennungen
Infinite Loop in Telerik Document Processing XLS Import
In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerProgress Software
≫
Produkt
Telerik Document Processing Libraries
Default Statusunaffected
Version
2026.3.811
Version <
2026.3.1006
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.076 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@progress.com | 7.3 | 3.9 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
https://www.telerik.com/document-processing-libraries/documentation/knowledge-base/kb-security-import-infinite-loop-cve-2026-106164