Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jxpf-xq2m-q525 | OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle |
Fri, 05 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openmcdf
Openmcdf openmcdf |
|
| CPEs | cpe:2.3:a:openmcdf:openmcdf:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openmcdf Project
Openmcdf Project openmcdf |
Openmcdf
Openmcdf openmcdf |
Mon, 01 Jun 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openmcdf Project
Openmcdf Project openmcdf |
|
| CPEs | cpe:2.3:a:openmcdf_project:openmcdf:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Openmcdf Project
Openmcdf Project openmcdf |
Mon, 11 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ironfede
Ironfede openmcdf |
|
| Vendors & Products |
Ironfede
Ironfede openmcdf |
Fri, 08 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. Prior to version 3.1.3, OpenMcdf does not detect cycles in the directory entry red-black tree of a Compound File Binary (CFB) document. A crafted CFB file with a cycle in the LeftSiblingID / RightSiblingID chain causes Storage.EnumerateEntries() and Storage.OpenStream() to loop indefinitely, consuming the calling thread with no possibility of recovery via try/catch. This issue has been patched in version 3.1.3. | |
| Title | OpenMcdf has an Infinite loop DoS via crafted CFB directory cycle | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T18:45:06.128Z
Reserved: 2026-04-20T18:18:50.681Z
Link: CVE-2026-41511
Updated: 2026-05-11T18:44:48.757Z
Status : Analyzed
Published: 2026-05-08T19:16:31.363
Modified: 2026-06-17T10:46:49.250
Link: CVE-2026-41511
No data.
OpenCVE Enrichment
Updated: 2026-05-10T21:24:56Z
Github GHSA