PT-2026-23860 · Xlnt · Xlnt
Oneafter
·
Published
2026-03-07
·
Updated
2026-03-10
·
CVE-2026-3664
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
xlnt versions up to 1.6.1
Description
An issue exists in the xlnt library, specifically within the
xlnt::detail::compound document::read directory function located in the source/detail/cryptography/compound document.cpp file. This relates to the Encrypted XLSX File Parser component and can lead to an out-of-bounds read condition. The issue is restricted to local execution and has been publicly disclosed.Recommendations
Apply patch 147 to resolve this issue.
Exploit
Fix
Buffer Overflow
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xlnt