CVE 6.2 MEDIUM

OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle_CVE-2026-41511

6.2 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. Prior to version 3.1.3, OpenMcdf does not detect cycles in the directory entry red-black tree of a Compound File Binary (CFB) document. A crafted CFB file with a cycle in the LeftSiblingID / RightSiblingID chain causes Storage.EnumerateEntries() and Storage.OpenStream() to loop indefinitely, consuming the calling thread with no possibility of recovery via try/catch. This issue has been patched in version 3.1.3.

Basic Information

ID CVE-2026-41511
Source GitHub_M
Published May 8, 2026 at 18:52

Affected Product

Vendor ironfede
Product openmcdf
Version < 3.1.3
Affected Versions ironfede openmcdf < 3.1.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.