exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand to gigabytes in memory, exhausting available resources and causing denial of service.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-24 01:16
Updated : 2026-08-31 20:52
NVD link : CVE-2026-78206
Mitre link : CVE-2026-78206
CVE.ORG link : CVE-2026-78206
JSON object : View
Products Affected
No product.
CWE
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
