{"id":"GHSA-523c-xh4g-mh5m","summary":"Denial of Service in Apache POI","details":"Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks:\n  - Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294)\n  - Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295)","aliases":["CVE-2017-12626"],"modified":"2026-06-09T10:30:14.243427058Z","published":"2021-01-14T19:18:22Z","database_specific":{"github_reviewed_at":"2020-11-06T18:56:32Z","nvd_published_at":"2018-01-29T17:29:00Z","cwe_ids":["CWE-835"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-12626"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:1322"},{"type":"PACKAGE","url":"https://github.com/apache/poi"},{"type":"WEB","url":"https://lists.apache.org/thread.html/453d9af5dbabaccd9afb58d27279a9dbfe8e35f4e5ea1645ddd6960b%40%3Cdev.poi.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/453d9af5dbabaccd9afb58d27279a9dbfe8e35f4e5ea1645ddd6960b@%3Cdev.poi.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuApr2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuapr2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/102879"}],"affected":[{"package":{"name":"org.apache.poi:poi","ecosystem":"Maven","purl":"pkg:maven/org.apache.poi/poi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.17"}]}],"versions":["3.0-FINAL","3.0.1-FINAL","3.0.2-FINAL","3.0.2-beta1","3.0.2-beta2","3.1-FINAL","3.1-beta1","3.1-beta2","3.10-FINAL","3.10-beta1","3.10-beta2","3.10.1","3.11","3.11-beta1","3.11-beta2","3.11-beta3","3.12","3.12-beta1","3.13","3.13-beta1","3.14","3.14-beta1","3.15","3.15-beta1","3.15-beta2","3.16","3.16-beta1","3.16-beta2","3.17-beta1","3.2-FINAL","3.5-FINAL","3.5-beta1","3.5-beta3","3.5-beta4","3.5-beta5","3.5-beta6","3.6","3.7","3.7-beta1","3.7-beta2","3.7-beta3","3.8","3.8-beta1","3.8-beta2","3.8-beta3","3.8-beta4","3.8-beta5","3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/01/GHSA-523c-xh4g-mh5m/GHSA-523c-xh4g-mh5m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}