CVE-2026-15274

LOW

lo48576 fbxcel Node Header parser.rs denial of service

Title source: cna
STIX 2.1

Description

A vulnerability was detected in lo48576 fbxcel up to 0.9.0. This affects an unknown part of the file src/pull_parser/v7400/parser.rs of the component Node Header Handler. The manipulation results in denial of service. The attack must be initiated from a local position. The exploit is now public and may be used. The pull request to fix this issue awaits acceptance.

References (7)

Core 7
Core References
Vdb Entry vdb-entry
VDB-377215 | lo48576 fbxcel Node Header parser.rs denial of service
https://vuldb.com/vuln/377215
Signature, Permissions Required signature permissions-required
VDB-377215 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/377215/cti
Third Party Advisory third-party-advisory
CVE-2026-15274 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15274
Third Party Advisory third-party-advisory
Submit #852441 | fbxcel <= 0.9.0 Denial of Service
https://vuldb.com/submit/852441
Exploit exploit issue-tracking
https://github.com/lo48576/fbxcel/issues/14
Patch issue-tracking patch
https://github.com/lo48576/fbxcel/pull/15

Scores

CVSS v3 3.3
EPSS 0.0012
EPSS Percentile 2.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (9)
lo48576/fbxcel 0.1
lo48576/fbxcel 0.2
lo48576/fbxcel 0.3
lo48576/fbxcel 0.4
lo48576/fbxcel 0.5
lo48576/fbxcel 0.6
lo48576/fbxcel 0.7
lo48576/fbxcel 0.8
lo48576/fbxcel 0.9.0
Published Jul 09, 2026
Tracked Since Jul 10, 2026