Medium severity5.5NVD Advisory· Published Mar 4, 2022· Updated Jun 17, 2026
CVE-2022-26336
CVE-2022-26336
Description
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.poi:poi-scratchpadMaven | >= 3.8-beta1, < 5.2.1 | 5.2.1 |
Affected products
6- Apache Software Foundation/poi-scratchpadv5Range: unspecified
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-mqvp-7rrg-9jxcghsaADVISORY
- lists.apache.org/thread/sprg0kq986pc2271dc3v2oxb1f9qx09jnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-26336ghsaADVISORY
- security.netapp.com/advisory/ntap-20221028-0006/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20221028-0006ghsaWEB
News mentions
0No linked articles in our index yet.