{"id":"CVE-2026-2703","summary":"xlnt-community xlnt Encrypted XLSX File base64.cpp decode_base64 off-by-one","details":"A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::decode_base64 of the file source/detail/cryptography/base64.cpp of the component Encrypted XLSX File Parser. Executing a manipulation can lead to off-by-one. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called f2d7bf494e5c52706843cf7eb9892821bffb0734. Applying a patch is advised to resolve this issue.","modified":"2026-08-12T16:24:55.747889Z","published":"2026-02-19T04:02:10.794Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-189","CWE-193"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2703.json"},"references":[{"type":"WEB","url":"https://github.com/xlnt-community/xlnt/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2703.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2703"},{"type":"ADVISORY","url":"https://vuldb.com/?id.346649"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.754377"},{"type":"REPORT","url":"https://github.com/xlnt-community/xlnt/issues/137"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.346649"},{"type":"FIX","url":"https://github.com/xlnt-community/xlnt/commit/f2d7bf494e5c52706843cf7eb9892821bffb0734"},{"type":"EVIDENCE","url":"https://github.com/oneafter/0128/blob/main/xl1/repro"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/xlnt-community/xlnt","events":[{"introduced":"0"},{"fixed":"f2d7bf494e5c52706843cf7eb9892821bffb0734"}],"database_specific":{"cpe":"cpe:2.3:a:xlnt-community:xlnt:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.6.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.6.0","1.6.1","v1.6.1","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.2.0","v1.1.0","v1.0.0","v0.9.2","v0.9.1","v0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2703.json","vanir_signatures_modified":"2026-08-12T16:24:55Z","vanir_signatures":[{"digest":{"line_hashes":["294004409167803484655518375459720785833","313182549887546401374845835312687812045","197694486794752061003407397536609331338","163469820562559622196221778517281111627","36376994209861132912143590274346680481","138679251401729705227171864261448809125"],"threshold":0.9},"id":"CVE-2026-2703-528e668f","signature_type":"Line","signature_version":"v1","source":"https://github.com/xlnt-community/xlnt/commit/f2d7bf494e5c52706843cf7eb9892821bffb0734","target":{"file":"source/detail/cryptography/base64.hpp"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/xlnt-community/xlnt/commit/f2d7bf494e5c52706843cf7eb9892821bffb0734","target":{"file":"source/detail/cryptography/base64.cpp","function":"decode_base64"},"deprecated":false,"digest":{"function_hash":"179078999246712399799297840132986866496","length":1866},"id":"CVE-2026-2703-a38bec37","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["9273301092784325900993085219243301676","266763168467957403350286018969559530578","225576704630723207781376261651428203497","170112818145254095508107194102109233977","159868310532218374090009129343719445577","264839308703357296641876567466675944712","151115812028466079329918454402709628369","154080546146703865969438363449523925441","297444467167055263089179413279243148032","296484806932856556260743982063427639474","293305128102122074427073065470901379424","187898350134461082785689390476853690245","47206974268772451270529500203223173690","258785949242237478525591266031771800070","146047813372830457530053073466772793000","244791488814487776790681145975645187857","321214378615948894194736783885961284069","121095137403607973959516212457596066596","209008564477809655580110007359204588069","57862371749751065298334194011945452635","284598283540837101875965790544749847542","129890764106088091252897207498430754818","304951345865246873887660504685687200786","20021767116230078231964686018052447929"],"threshold":0.9},"id":"CVE-2026-2703-b117b1c0","signature_type":"Line","signature_version":"v1","source":"https://github.com/xlnt-community/xlnt/commit/f2d7bf494e5c52706843cf7eb9892821bffb0734","target":{"file":"source/detail/cryptography/base64.cpp"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}