CVE-2026-41511Openmcdf · Openmcdf
Vulnerability data via NVD (ingested)
OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. Prior to version 3.1.3, OpenMcdf does not detect cycles in the directory entry red-black tree of a Compound File Binary (CFB) document. A crafted CFB file with a cycle in the LeftSiblingID / RightSiblingID chain causes Storage.EnumerateEntries() and Storage.OpenStream() to loop indefinitely, consuming the calling thread with no possibility of recovery via try/catch. This issue has been patched in version 3.1.3.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-41511product:"Openmcdf Openmcdf"http.html:"Openmcdf"More intel sources (5)
vuln:CVE-2026-41511vulnerabilities.cve_id: CVE-2026-41511CVE-2026-41511CVE-2026-41511"CVE-2026-41511" exploit -site:nvd.nist.gov