SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-59933

HIGH · CVSS 7.5 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The PhpSpreadsheet library is vulnerable in multiple versions, allowing an attacker to craft a malicious XLS/OLE file that can cause a denial of service by exhausting the PHP process's memory through infinite sector chain loops. This vulnerability primarily affects applications that accept user-uploaded spreadsheet files, making it critical for developers and organizations using PhpSpreadsheet to upgrade to the patched versions to mitigate potential service disruptions. Prioritization is essential for those managing web applications or services that handle spreadsheet uploads.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59933
Severity
HIGH
CVSS
7.5
EPSS
0.38%

Original NVD Description

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the OLE reader follows sector chains from attacker-controlled XLS/OLE metadata without detecting cycles or enforcing a maximum chain length. A tiny malformed .xls/OLE file can set the small-block depot sector chain to point back to itself. During normal XLS detection, OLERead::read() appends the same sector data repeatedly until the PHP process exhausts memory. This is reachable from Reader\Xls::canRead() and therefore from automatic spreadsheet type detection. Applications that accept attacker-controlled spreadsheet uploads can suffer denial of service from a very small file. This issue has been fixed in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18 and 1.30.6.