CVE-2026-78206: Exceljs

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand to gigabytes in memory, exhausting available resources and causing denial of service.

Affected products

  • Exceljs Exceljs: up to and including 4.4.0

Published 2026-08-24. Last modified 2026-08-31.