Impact
The vulnerability is an infinite loop triggered when importing a specially‑crafted XLS file into the SpreadProcessing library. The import timeout is ignored, causing the CPU thread to consume 100% of processor resources and leaving the process unresponsive. This results in a denial of service that can affect an entire application or system depending on how the library is used.
Affected Systems
Affected vendors include Progress Software, which distributes the Telerik Document Processing Libraries. Versions of the SpreadProcessing library older than 2026.3.1006 contain the flaw; upgrading to 2026.3.1006 or later removes the vulnerability.
Risk and Exploitability
The CVSS score of 7.3 classifies the issue as high severity. No EPSS score is published, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local or remote user able to supply an XLS file to the application; the attacker can trigger the infinite loop by crafting the file, forcing the process into an unresponsive state. The exact likelihood of exploitation cannot be quantified without EPSS data, but the high CVSS indicates a significant risk for systems presenting the vulnerable library to untrusted input.
OpenCVE Enrichment