Description
In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.
Published: 2026-10-07
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an infinite loop triggered when importing a specially‑crafted XLS file into the SpreadProcessing library. The import timeout is ignored, causing the CPU thread to consume 100% of processor resources and leaving the process unresponsive. This results in a denial of service that can affect an entire application or system depending on how the library is used.

Affected Systems

Affected vendors include Progress Software, which distributes the Telerik Document Processing Libraries. Versions of the SpreadProcessing library older than 2026.3.1006 contain the flaw; upgrading to 2026.3.1006 or later removes the vulnerability.

Risk and Exploitability

The CVSS score of 7.3 classifies the issue as high severity. No EPSS score is published, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a local or remote user able to supply an XLS file to the application; the attacker can trigger the infinite loop by crafting the file, forcing the process into an unresponsive state. The exact likelihood of exploitation cannot be quantified without EPSS data, but the high CVSS indicates a significant risk for systems presenting the vulnerable library to untrusted input.

Generated by OpenCVE AI on October 7, 2026 at 19:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or upgrade to version 2026.3.1006 or later.
  • Avoid importing XLS files from untrusted or unknown sources until a fix is applied.
  • If an upgrade is not immediately possible, monitor the application’s CPU usage and consider configuring stricter import timeouts or disabling the XLS import feature for critical hosts.

Generated by OpenCVE AI on October 7, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.
Title Infinite Loop in Telerik Document Processing XLS Import
Weaknesses CWE-835
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-10-07T19:23:45.883Z

Reserved: 2026-10-06T15:51:20.077Z

Link: CVE-2026-106164

cve-icon Vulnrichment

Updated: 2026-10-07T19:18:39.429Z

cve-icon NVD

Status : Received

Published: 2026-10-07T19:17:31.987

Modified: 2026-10-07T20:17:08.537

Link: CVE-2026-106164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T19:30:03Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')