Infinite Loop Vulnerability in Progress® Telerik® Document Processing Library
CVE-2026-106164

7.3HIGH

What is CVE-2026-106164?

A vulnerability in Progress® Telerik® Document Processing SpreadProcessing library allows attackers to exploit a flawed XLS file import mechanism. Specifically, when importing a corrupted XLS file, the library enters an infinite loop, causing an unresponsive CPU thread. This leads to denial of service, as the import operation ignores usual timeout settings. Users of affected versions are advised to upgrade to the latest version to mitigate this issue.

Affected Version(s)

Telerik Document Processing Libraries 2026.3.811 < 2026.3.1006

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ezinne Kalu
.