CVE detail
CVE-2026-2703
A weakness has been identified in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::decode_base64 of the file source/detail/cryptography/base64.cpp of the component Encrypted XLSX File Parser. Executing a manipulation can lead to off-by-one. The attack requires local access. The exploit has been made available to the public and could be used for attacks. This patch is called f2d7bf494e5c52706843cf7eb9892821bffb0734. Applying a patch is advised to resolve this issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- https://vuldb.com/?submit.754377vuldb.com
No excerpt available.
Exploitvuldb.comFeb 19, 2026, 7:17 AM - https://vuldb.com/?id.346649vuldb.com
No excerpt available.
Exploitvuldb.comFeb 19, 2026, 7:17 AM - https://vuldb.com/?ctiid.346649vuldb.com
No excerpt available.
Exploitvuldb.comFeb 19, 2026, 7:17 AM No excerpt available.
Exploitgithub.comFeb 19, 2026, 7:17 AMNo excerpt available.
Exploitgithub.comFeb 19, 2026, 7:17 AM- https://github.com/xlnt-community/xlnt/github.com
No excerpt available.
Exploitgithub.comFeb 19, 2026, 7:17 AM No excerpt available.
Exploitgithub.comFeb 19, 2026, 7:17 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-5123CVSS 6.3 · Medium
A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/packet/bgp/bgp.go. Executing a manipulation of the argument dat…
- CVE-2026-14899CVSS 7.5 · High
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read fr…
- CVE-2026-44687CVSS 3.7 · Low
In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the in…
- CVE-2026-50497CVSS 6.5 · Medium
Off-by-one error in Windows Remote Desktop Protocol allows an unauthorized attacker to disclose information over a network.
- CVE-2026-58380CVSS 7.3 · High
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of…
- CVE-2026-14787CVSS 1.9 · Low
A weakness has been identified in radareorg radare2 up to 6.1.6. Affected is the function cmd_print in the library libr/core/cmd_print.inc of the component pb Print Command Handle…