Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jxpf-xq2m-q525 | OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle |
Mon, 11 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ironfede
Ironfede openmcdf |
|
| Vendors & Products |
Ironfede
Ironfede openmcdf |
Fri, 08 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. Prior to version 3.1.3, OpenMcdf does not detect cycles in the directory entry red-black tree of a Compound File Binary (CFB) document. A crafted CFB file with a cycle in the LeftSiblingID / RightSiblingID chain causes Storage.EnumerateEntries() and Storage.OpenStream() to loop indefinitely, consuming the calling thread with no possibility of recovery via try/catch. This issue has been patched in version 3.1.3. | |
| Title | OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T18:45:06.128Z
Reserved: 2026-04-20T18:18:50.681Z
Link: CVE-2026-41511
Updated: 2026-05-11T18:44:48.757Z
Status : Awaiting Analysis
Published: 2026-05-08T19:16:31.363
Modified: 2026-05-13T17:26:28.013
Link: CVE-2026-41511
No data.
OpenCVE Enrichment
Updated: 2026-05-10T21:24:56Z
Github GHSA