In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service. | |
| Title | Infinite Loop in Telerik Document Processing XLS Import | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-10-07T19:23:45.883Z
Reserved: 2026-10-06T15:51:20.077Z
Link: CVE-2026-106164
No data.
Status : Received
Published: 2026-10-07T19:17:31.987
Modified: 2026-10-07T19:17:31.987
Link: CVE-2026-106164
No data.
OpenCVE Enrichment
Updated: 2026-10-07T19:30:03Z
Weaknesses