Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).
History

Thu, 28 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.01797}

epss

{'score': 0.02422}


cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2018-01-29T17:00:00.000Z

Updated: 2026-05-28T17:54:38.163Z

Reserved: 2017-08-07T00:00:00.000Z

Link: CVE-2017-12626

cve-icon Vulnrichment

Updated: 2024-08-05T18:43:56.421Z

cve-icon NVD

Status : Modified

Published: 2018-01-29T17:29:00.410

Modified: 2026-05-28T19:16:24.050

Link: CVE-2017-12626

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-01-26T00:00:00Z

Links: CVE-2017-12626 - Bugzilla