CVE-2026-106164
Received Received - Intake

Infinite Loop in Telerik Document Processing SpreadProcessing Library

Vulnerability report for CVE-2026-106164, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Progress Software Corporation

Description

In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progress Software Telerik Document Processing Libraries 2026.3.811

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an infinite loop issue in the Progress Telerik Document Processing SpreadProcessing library before version 2026.3.1006. It occurs when importing a specially crafted XLS file with corruption, causing the import process to hang indefinitely. The CPU thread becomes unresponsive, leading to a denial of service condition.

Detection Guidance

Detection involves monitoring for unresponsive CPU threads during XLS file imports. Check for processes consuming excessive CPU when handling Telerik Document Processing SpreadProcessing library operations. No specific commands are provided in the available resources.

Impact Analysis

This vulnerability can cause system slowdowns or complete unresponsiveness when processing malicious XLS files. It may lead to denial of service, disrupting normal operations and requiring a restart to recover. Systems handling untrusted files are particularly at risk.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by causing a denial of service through CPU exhaustion during XLS file processing. Uncontrolled resource consumption may lead to system unavailability, which could violate availability requirements in both regulations.

Mitigation Strategies

Update the Progress Telerik Document Processing SpreadProcessing library to version 2026.3.1006 or later. Disable or restrict access to XLS file import functionality if immediate updates are not possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106164. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart