CVE-2026-59932
Received Received - Intake

Memory Exhaustion in PhpSpreadsheet Gnumeric Reader

Vulnerability report for CVE-2026-59932, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: GitHub, Inc.

Description

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the Gnumeric reader reads attacker-supplied .gnumeric files into memory and, when the file starts with gzip magic bytes, calls gzdecode() on the full compressed contents without enforcing a decompressed-size limit. A very small compressed .gnumeric file can expand to data larger than the PHP memory limit and crash the process during Gnumeric::canRead() before the file is rejected or fully parsed. This is reachable through normal file-type detection and Gnumeric loading paths, so applications that accept attacker-controlled spreadsheet uploads can suffer denial of service. This issue has been fixed in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18 and 1.30.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-29
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 11 associated CPEs
Vendor Product Version / Range
phpspreadsheet phpspreadsheet From 1.30.0 (inc) to 5.8.0 (inc)
phpspreadsheet phpspreadsheet 5.8.1
phpspreadsheet phpspreadsheet 3.10.7
phpspreadsheet phpspreadsheet 2.4.7
phpspreadsheet phpspreadsheet 2.1.18
phpoffice phpspreadsheet From 1.30.5 (inc) to 5.8.0 (inc)
phpoffice phpspreadsheet 1.30.6
phpoffice phpspreadsheet 2.1.18
phpoffice phpspreadsheet 2.4.7
phpoffice phpspreadsheet 3.10.7
phpoffice phpspreadsheet 5.8.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-409 The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects PhpSpreadsheet, a PHP library for spreadsheet files. It allows attackers to upload specially crafted .gnumeric files that, when processed, can cause memory exhaustion. The Gnumeric reader decompresses gzip-compressed files without enforcing a size limit, leading to crashes during file type detection or parsing.

Detection Guidance

Check if your PhpSpreadsheet version is between 1.30.5 and 5.8.0. Run: composer show phpoffice/phpspreadsheet. If vulnerable, update to versions 1.30.6, 2.1.18, 2.4.7, 3.10.7, or 5.8.1 or later.

Impact Analysis

If you use PhpSpreadsheet in an application that accepts user-uploaded spreadsheet files, an attacker could exploit this to crash your application through a denial-of-service attack. This could disrupt services or make your system unavailable until manually restarted.

Compliance Impact

This vulnerability primarily impacts availability by causing denial of service through memory exhaustion when processing malicious .gnumeric files. It does not directly affect data confidentiality or integrity, which are key concerns for GDPR and HIPAA compliance. However, service disruptions could indirectly impact compliance by preventing timely access to required data.

Mitigation Strategies

Upgrade PhpSpreadsheet to a patched version (1.30.6, 2.1.18, 2.4.7, 3.10.7, or 5.8.1+). If immediate upgrade isn't possible, restrict file uploads to trusted sources and implement size limits on uploaded files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59932. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart