A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::decode_base64 of the file source/detail/cryptography/base64.cpp of the component Encrypted XLSX File Parser. Executing a manipulation can lead to off-by-one. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called f2d7bf494e5c52706843cf7eb9892821bffb0734. Applying a patch is advised to resolve this issue.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xlnt-community
Xlnt-community xlnt |
|
| Vendors & Products |
Xlnt-community
Xlnt-community xlnt |
Thu, 19 Feb 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::decode_base64 of the file source/detail/cryptography/base64.cpp of the component Encrypted XLSX File Parser. Executing a manipulation can lead to off-by-one. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called f2d7bf494e5c52706843cf7eb9892821bffb0734. Applying a patch is advised to resolve this issue. | |
| Title | xlnt-community xlnt Encrypted XLSX File base64.cpp decode_base64 off-by-one | |
| Weaknesses | CWE-189 CWE-193 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-02-19T04:02:10.794Z
Updated: 2026-02-19T04:02:10.794Z
Reserved: 2026-02-18T17:59:02.756Z
Link: CVE-2026-2703
No data.
Status : Awaiting Analysis
Published: 2026-02-19T07:17:49.477
Modified: 2026-02-19T15:52:39.260
Link: CVE-2026-2703
No data.