Infinite Loop Vulnerability in Progress® Telerik® Document Processing Library
CVE-2026-106164
7.3HIGH
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 7 October 2026
What is CVE-2026-106164?
A vulnerability in Progress® Telerik® Document Processing SpreadProcessing library allows attackers to exploit a flawed XLS file import mechanism. Specifically, when importing a corrupted XLS file, the library enters an infinite loop, causing an unresponsive CPU thread. This leads to denial of service, as the import operation ignores usual timeout settings. Users of affected versions are advised to upgrade to the latest version to mitigate this issue.
Affected Version(s)
Telerik Document Processing Libraries 2026.3.811 < 2026.3.1006