kreuzberg is vulnerable to Denial of Service (DoS)
30
Low Risk
Affected versions of this package are vulnerable to denial of service when processing specially crafted XLSX files with extreme or sparse declared dimensions. Such files can trigger excessive memory allocation, potentially leading to out-of-memory conditions and application crashes. The patched version introduces safeguards that detect pathological bounding boxes and process sparse sheets safely, preventing excessive memory allocation.
You are affected if you are using a version that falls within the vulnerable range.
kreuzberg is vulnerable to Denial of Service (DoS) in versions 4.0.0 - 4.2.1.
Upgrade the kreuzberg library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant