Vulnerability Details CVE-2026-41511
OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. Prior to version 3.1.3, OpenMcdf does not detect cycles in the directory entry red-black tree of a Compound File Binary (CFB) document. A crafted CFB file with a cycle in the LeftSiblingID / RightSiblingID chain causes Storage.EnumerateEntries() and Storage.OpenStream() to loop indefinitely, consuming the calling thread with no possibility of recovery via try/catch. This issue has been patched in version 3.1.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.4%
CVSS Severity
CVSS v3 Score 6.2
Products affected by CVE-2026-41511
-
cpe:2.3:a:openmcdf:openmcdf:1.4.2
-
cpe:2.3:a:openmcdf:openmcdf:1.5.0
-
cpe:2.3:a:openmcdf:openmcdf:1.5.3
-
cpe:2.3:a:openmcdf:openmcdf:1.5.3.1
-
cpe:2.3:a:openmcdf:openmcdf:1.5.3.2
-
cpe:2.3:a:openmcdf:openmcdf:1.5.3.3
-
cpe:2.3:a:openmcdf:openmcdf:1.5.4
-
cpe:2.3:a:openmcdf:openmcdf:1.5.5
-
cpe:2.3:a:openmcdf:openmcdf:2.1.1.29598
-
cpe:2.3:a:openmcdf:openmcdf:2.1.2.1274
-
cpe:2.3:a:openmcdf:openmcdf:2.1.3.34720
-
cpe:2.3:a:openmcdf:openmcdf:2.1.3.34730
-
cpe:2.3:a:openmcdf:openmcdf:2.1.4.23498
-
cpe:2.3:a:openmcdf:openmcdf:2.1.5.22659
-
cpe:2.3:a:openmcdf:openmcdf:2.1.6.28924
-
cpe:2.3:a:openmcdf:openmcdf:2.2.0.1
-
cpe:2.3:a:openmcdf:openmcdf:2.2.1.2
-
cpe:2.3:a:openmcdf:openmcdf:2.2.1.3
-
cpe:2.3:a:openmcdf:openmcdf:2.2.1.4
-
cpe:2.3:a:openmcdf:openmcdf:2.2.1.5
-
cpe:2.3:a:openmcdf:openmcdf:2.2.1.6
-
cpe:2.3:a:openmcdf:openmcdf:2.2.1.9
-
cpe:2.3:a:openmcdf:openmcdf:2.3.0.0
-
cpe:2.3:a:openmcdf:openmcdf:2.3.1.0
-
cpe:2.3:a:openmcdf:openmcdf:2.4.0.0
-
cpe:2.3:a:openmcdf:openmcdf:2.4.1.0
-
cpe:2.3:a:openmcdf:openmcdf:3.0.0
-
cpe:2.3:a:openmcdf:openmcdf:3.0.1
-
cpe:2.3:a:openmcdf:openmcdf:3.0.2
-
cpe:2.3:a:openmcdf:openmcdf:3.0.3
-
cpe:2.3:a:openmcdf:openmcdf:3.1.0
-
cpe:2.3:a:openmcdf:openmcdf:3.1.1
-
cpe:2.3:a:openmcdf:openmcdf:3.1.2