cvedb.io
CVE-2026-41511
MEDIUM · CVSS 6.2
EPSS exploitation probability: 0%
Published 2026-05-08T19:16:31.363 · Last modified 2026-06-17T10:46:49.250

Summary

OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. Prior to version 3.1.3, OpenMcdf does not detect cycles in the directory entry red-black tree of a Compound File Binary (CFB) document. A crafted CFB file with a cycle in the LeftSiblingID / RightSiblingID chain causes Storage.EnumerateEntries() and Storage.OpenStream() to loop indefinitely, consuming the calling thread with no possibility of recovery via try/catch. This issue has been patched in version 3.1.3.

Affected products

openmcdf — openmcdf

Does this affect you?

Add your gear to cvedb and we'll alert you only when openmcdf ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.