CVE-2026-3665

Severity CVSS v4.0:
MEDIUM
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
07/03/2026
Last modified:
07/03/2026

Description

A vulnerability was identified in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xlsx_consumer::read_office_document of the file source/detail/serialization/xlsx_consumer.cpp of the component XLSX File Parser. The manipulation leads to null pointer dereference. The attack must be carried out locally. The exploit is publicly available and might be used.