


Perceptive Security
SOC/SIEM Consultancy

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.…
Published:
27 juli 2026 om 22:00:00
Alert date:
28 juli 2026 om 20:07:40
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A denial-of-service vulnerability exists in PhpSpreadsheet, a pure PHP library for reading and writing spreadsheet files. The Gnumeric file reader calls gzdecode() on compressed file contents without enforcing a decompressed-size limit, allowing a small crafted .gnumeric file to expand beyond PHP memory limits and crash the process. This is triggered during the Gnumeric::canRead() file-type detection phase, before the file is fully parsed or rejected. Affected versions span multiple release branches including 1.x through 5.x. Applications that accept attacker-controlled spreadsheet uploads are at risk of process crashes and service disruption. Fixes have been released in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6. This is a classic zip-bomb style attack vector applied to the gzip decompression path.
Technical details
Mitigation steps:
Affected products:
PhpSpreadsheet
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-59932
https://github.com/PHPOffice/PhpSpreadsheet/commit/85f2556b0bf5269061bf45932ecda8a128d81750
https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/1.30.6
https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.1.18
https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.4.7
https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/3.10.7
https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/5.8.1
https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-2mrg-gjxq-2gvr
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
