Ghostwire

CVE-2026-78206: exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory without limits on entry...

HIGH CVSS 7.5 Exploit Available

Published: August 24, 2026 | Last Modified: August 24, 2026

Description

exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand to gigabytes in memory, exhausting available resources and causing denial of service.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

References