CVE-2026-106164: Infinite Loop in Telerik Document Processing XLS Import
In Progress® Telerik® Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Telerik Document Processing SpreadProcessingto a version that resolves this vulnerability.Fixed in 2026.3.1006
Event History
Frequently Asked Questions
Which installations are affected?
Progress Telerik Document Processing SpreadProcessing versions prior to 2026.3.1006 are affected. Installations using XLS import functionality are the relevant exposure point.
What is required to trigger the issue?
An attacker needs an XLS file containing specifically targeted corruption and must cause it to be imported by the affected library. The supplied severity vector indicates no privileges or user interaction are required for exploitation.
Can an import timeout prevent the denial of service?
No. For the crafted XLS input, the import timeout is ignored, allowing an unresponsive CPU thread and denial-of-service condition.
What is the available remediation?
Upgrade SpreadProcessing to version 2026.3.1006 or later. The vulnerability affects versions before that release.