CVE-2026-3665
LOWxlnt-community xlnt <=1.6.1 - Memory Corruption
Title source: llmDescription
A vulnerability was identified in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xlsx_consumer::read_office_document of the file source/detail/serialization/xlsx_consumer.cpp of the component XLSX File Parser. The manipulation leads to null pointer dereference. The attack must be carried out locally. The exploit is publicly available and might be used.
References (6)
Scores
CVSS v3
3.3
EPSS
0.0001
EPSS Percentile
2.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Classification
CWE
CWE-404
CWE-476
Status
draft
Timeline
Published
Mar 07, 2026
Tracked Since
Mar 07, 2026