Infinite Loop Vulnerability (CVE-2026-106164)
Description
October 2026 - CVE-2026-106164
- Telerik Document Processing v2026.3.923 or earlier.
What Are the Impacts
In Telerik Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.
Issue
- CWE-835: Loop with unreachable exit condition ('infinite loop')
Solution
We have addressed the issue and the Progress Telerik team strongly recommends performing an upgrade to the latest version listed in the table below.
| Current Version | Update to |
|---|---|
<= 2026.3.923 | >= 2026.3.1006 (2026 Q3) |
Follow the update instructions for precise instructions. All customers who have a license for Telerik Document Processing can access their downloads here Product Downloads | Your Account.
Notes
- If you have any questions or concerns related to this issue, open a new Technical Support case in Your Account | Support Center. Technical Support is available to customers with an active support plan.
- We would like to thank Ezinne Kalu for their cooperation and responsible disclosure through the Progress Software vulnerability disclosure program.
External References
CVE-2026-106164 (High)
CVSS: 7.3
In Telerik Document Processing SpreadProcessing library, versions prior to 2026.3.1006, an infinite loop vulnerability exists when importing an XLS file with a specifically-targted corruption, the import timeout is ignored resulting in an unresponsive CPU thread and denial of service.
Finder: Ezinne Kalu