Junglewise Threat Intelligence

CVE-2026-45785: OpenMcdf infinite loop in DirectoryTree name-lookup

CVE-2026-45785 · Severity: medium · CVSS 6.2 · Published 2026-07-17

Vendors: NuGet.

Executive brief

OpenMcdf is a software library used by developers to read and write Compound File Binary (CFB) files, such as older Microsoft Office documents (.doc, .xls) and Outlook messages (.msg). A vulnerability in this library allows a specially crafted file to trigger an infinite loop when the software attempts to look up a file or folder name within the document. This results in the application consuming 100% of the processor's resources and becoming completely unresponsive, potentially causing a service outage or system hang.

Technical details

A vulnerability exists in the Binary Search Tree (BST) name-lookup loop within `DirectoryTree.TryGetDirectoryEntry`. By constructing a CFB file with cyclic Left/Right sibling links that satisfy the per-step BST-order check in `TryGetSibling`, an attacker can cause the `while (child is not null)` loop to run indefinitely. The library lacks cycle detection in this specific code path, which is reachable via public APIs including `RootStorage.OpenStorage`, `TryOpenStorage`, `OpenStream`, and `TryOpenStream`. While other parts of the library use Brent's algorithm for cycle detection during enumeration, the name-lookup path remains unprotected in affected versions. This results in a denial of service (100% CPU usage) that cannot be recovered without terminating the process. The issue is resolved in version 3.1.4 by enforcing BST validation on all directory entry sibling accesses.

Affected products

  • openmcdf OpenMcdf <= 3.1.3

Timeline

  • 2026-05-13: patched: Fix committed to repository
  • 2026-05-14: advisory: GitHub Security Advisory published
  • 2026-07-17: disclosed: CVE published to NVD

References

Related threats