Intel

AIKIDO-2026-10125

kreuzberg is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

30

Low Risk

This Affects:

PYTHONkreuzberg
4.0.0 - 4.2.1
Fixed in 4.2.2

TL;DR

Affected versions of this package are vulnerable to denial of service when processing specially crafted XLSX files with extreme or sparse declared dimensions. Such files can trigger excessive memory allocation, potentially leading to out-of-memory conditions and application crashes. The patched version introduces safeguards that detect pathological bounding boxes and process sparse sheets safely, preventing excessive memory allocation.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

kreuzberg is vulnerable to Denial of Service (DoS) in versions 4.0.0 - 4.2.1.

How to fix this

Upgrade the kreuzberg library to the patch version.

Background Info