GHSA-523c-xh4g-mh5mHighCVSS 7.5

Denial of Service in Apache POI

Published
January 14, 2021
Last Modified
June 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks:

  • Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294)
  • Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295)

🎯 Affected products1

  • maven/org.apache.poi:poi:< 3.17

🔗 References (15)