CVE-2026-106164: Progress Software Telerik Document Processing Libraries
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.
Affected products
- Progress Software Telerik Document Processing Libraries: from 2026.3.811, before 2026.3.1006 (fixed in 2026.3.1006)
Published 2026-10-07. Last modified 2026-10-08.