GHSA-mqvp-7rrg-9jxc · Severity: medium · Ecosystem: maven — Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpad
A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1.
Conclusion & alert: CVE-2022-26336 is rated Low Risk (26.4/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.05%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.52% | 0.05% | -0.48% |
| 2 | 2025-11-18 | 0.03% | 0.52% | +0.49% |
| 3 | 2025-03-30 | — | 0.03% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
GHSA-mqvp-7rrg-9jxc · Severity: medium · Ecosystem: maven — Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpad
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2022-26336 |
ubuntu
|
low | CVE-2022-26336 low priority: Ubuntu including 2 source packages (libapache-poi-java, lucene-solr), 28 status rows across 14 suites (bionic, focal, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): needs-triage 15, ignored 13. | https://ubuntu.com/security/CVE-2022-26336 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | poi | < 5.2.1 | cpe:2.3:a:apache:poi:*:*:*:*:*:*:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* |
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/sprg0kq986pc2271dc3v2oxb1f9qx09j | Mailing List Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20221028-0006/ | Third Party Advisory |