top of page
perceptive_background_267k.jpg

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.…

Published:

28 July 2026 at 00:00:00

Alert date:

28 July 2026 at 22:07:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

A denial-of-service vulnerability exists in PhpSpreadsheet, a pure PHP library for reading and writing spreadsheet files. The OLE reader follows sector chains from attacker-controlled XLS/OLE metadata without detecting cycles or enforcing a maximum chain length. A tiny malformed .xls/OLE file can set the small-block depot sector chain to point back to itself, causing OLERead::read() to append the same sector data repeatedly until the PHP process exhausts memory. This vulnerability is reachable from Reader\Xls::canRead() and automatic spreadsheet type detection. Applications that accept attacker-controlled spreadsheet uploads are at risk of denial of service from a very small file. Affected versions span multiple release branches including 1.x through 5.x. Fixes have been released in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6.

Technical details

Mitigation steps:

Affected products:

PhpSpreadsheet 1.x up to and including 1.30.5
PhpSpreadsheet 2.0.0 through 2.1.17
PhpSpreadsheet 2.2.0 through 2.4.6
PhpSpreadsheet 3.3.0 through 3.10.6
PhpSpreadsheet 4.0.0 through 5.8.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page