← Back to CVE search

CVE-2026-78206

exceljs-hardened

Description

exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand to gigabytes in memory, exhausting available resources and causing denial of service.

CVSS 7.5EPSS 0.44600000000000006%Risk 0.78
View source
Published
2026-08-24 01:16:57
Affected versions
<5.0.0
Type
Library
Last modified
2026-08-26 19:17:10
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H