<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 16:40:53 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-369668</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-369668</link>
      <description>EUVD-2026-369668</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-369668</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53752</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53752</link>
      <description>&lt;p&gt;docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn style inheritance chain without cycle detection. A well-formed DOCX containing mutually based styles causes unbounded recursion in PropertyResolver.fillPPrStack and related effective-style resolution paths, resulting in StackOverflowError. Server-side conversion and table-of-contents processing of an untrusted document can terminate a worker thread, degrade a thread pool, or deny service, although isolation in disposable workers or safe containment of StackOverflowError can reduce the practical effect. The fix adds cyclic-style tracking and CyclicStylesException handling. This issue is fixed in version 11.5.14.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn style inheritance chain without cycle detection. A well-formed DOCX containing mutually based styles causes unbounded recursion in PropertyResolver.fillPPrStack and related effective-style resolution paths, resulting in StackOverflowError. Server-side conversion and table-of-contents processing of an untrusted document can terminate a worker thread, degrade a thread pool, or deny service, although isolation in disposable workers or safe containment of StackOverflowError can reduce the practical effect. The fix adds cyclic-style tracking and CyclicStylesException handling. This issue is fixed in version 11.5.14.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53752</guid>
    </item>
    <item>
      <title>GHSA-gc95-3vw8-vg43 — docx4j: Stack Overflow via Cyclic `w:basedOn` Style Chain leads to Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gc95-3vw8-vg43</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.docx4j:docx4j-core&lt;/p&gt;
&lt;p&gt;### Summary
docx4j&amp;#39;s `PropertyResolver` and several adjacent helpers recursively walk the OpenXML style inheritance chain (`w:basedOn`) without cycle detection.&lt;/p&gt;
&lt;p&gt;A WordprocessingML document containing a cyclic style chain (for example, Style A based on B and Style B based on A) causes unbounded recursion and a `java.lang.StackOverflowError` within the property-resolution code path.&lt;/p&gt;
&lt;p&gt;These helpers are used by operations that require effective style resolution, including common conversion and TOC-related paths.  As a result, most server-side pipelines that accept a user-supplied docx and process it through docx4j can likely be crashed by a file containing a cyclic style reference.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Representative snippet: `PropertyResolver.fillPPrStack`&lt;/p&gt;
&lt;p&gt;```java
private void fillPPrStack(String styleId, Stack&amp;lt;PPr&amp;gt; pPrStack) {
    Style style = liveStyles.get(styleId);
    ...
    // if it is based on, recurse
    if (style.getBasedOn() == null) {
        log.debug(&amp;#34;Style &amp;#34; + styleId + &amp;#34; is a root style.&amp;#34;);
    } else if (style.getBasedOn().getVal() != null) {
        String basedOnStyleName = style.getBasedOn().getVal();
        fillPPrStack(basedOnStyleName, pPrStack);   // ← unbounded recursion
        ...
```&lt;/p&gt;
&lt;p&gt;### Impact
This is a denial of service against a server-side application that processes untrusted docx files via docx4j.&lt;/p&gt;
&lt;p&gt;An upload causes the processing thread to be terminated with `StackOverflowError` which may crash the worker thread, degrade the thread pool, or eva…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.docx4j:docx4j-core&lt;/p&gt;
&lt;p&gt;### Summary
docx4j&amp;#39;s `PropertyResolver` and several adjacent helpers recursively walk the OpenXML style inheritance chain (`w:basedOn`) without cycle detection.&lt;/p&gt;
&lt;p&gt;A WordprocessingML document containing a cyclic style chain (for example, Style A based on B and Style B based on A) causes unbounded recursion and a `java.lang.StackOverflowError` within the property-resolution code path.&lt;/p&gt;
&lt;p&gt;These helpers are used by operations that require effective style resolution, including common conversion and TOC-related paths.  As a result, most server-side pipelines that accept a user-supplied docx and process it through docx4j can likely be crashed by a file containing a cyclic style reference.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;Representative snippet: `PropertyResolver.fillPPrStack`&lt;/p&gt;
&lt;p&gt;```java
private void fillPPrStack(String styleId, Stack&amp;lt;PPr&amp;gt; pPrStack) {
    Style style = liveStyles.get(styleId);
    ...
    // if it is based on, recurse
    if (style.getBasedOn() == null) {
        log.debug(&amp;#34;Style &amp;#34; + styleId + &amp;#34; is a root style.&amp;#34;);
    } else if (style.getBasedOn().getVal() != null) {
        String basedOnStyleName = style.getBasedOn().getVal();
        fillPPrStack(basedOnStyleName, pPrStack);   // ← unbounded recursion
        ...
```&lt;/p&gt;
&lt;p&gt;### Impact
This is a denial of service against a server-side application that processes untrusted docx files via docx4j.&lt;/p&gt;
&lt;p&gt;An upload causes the processing thread to be terminated with `StackOverflowError` which may crash the worker thread, degrade the thread pool, or eva…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gc95-3vw8-vg43</guid>
    </item>
  </channel>
</rss>
