CVE-2026-41511

MEDIUM

OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle

Title source: cna
STIX 2.1

Description

OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. Prior to version 3.1.3, OpenMcdf does not detect cycles in the directory entry red-black tree of a Compound File Binary (CFB) document. A crafted CFB file with a cycle in the LeftSiblingID / RightSiblingID chain causes Storage.EnumerateEntries() and Storage.OpenStream() to loop indefinitely, consuming the calling thread with no possibility of recovery via try/catch. This issue has been patched in version 3.1.3.

Scores

CVSS v3 6.2
EPSS 0.0001
EPSS Percentile 3.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-835
Status published
Products (2)
ironfede/openmcdf < 3.1.3
nuget/OpenMcdf 0 - 3.1.3NuGet
Published May 08, 2026
Tracked Since May 09, 2026