🔐 CVE Alert

CVE-2026-106164

HIGH 7.3

Infinite Loop in Telerik Document Processing XLS Import

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.

CWE CWE-835
Vendor progress software
Product telerik document processing libraries
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for progress software telerik document processing libraries

Be the first to know when new high vulnerabilities affecting progress software telerik document processing libraries are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

Progress Software / Telerik Document Processing Libraries
2026.3.811 < 2026.3.1006

References

NVD ↗ CVE.org ↗ EPSS Data ↗
telerik.com: https://www.telerik.com/document-processing-libraries/documentation/knowledge-base/kb-security-import-infinite-loop-cve-2026-106164

Credits

Ezinne Kalu