CVE-2026-59933
Received Received - Intake

Memory Exhaustion in PhpSpreadsheet via Malformed XLS Files

Vulnerability report for CVE-2026-59933, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: GitHub, Inc.

Description

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the OLE reader follows sector chains from attacker-controlled XLS/OLE metadata without detecting cycles or enforcing a maximum chain length. A tiny malformed .xls/OLE file can set the small-block depot sector chain to point back to itself. During normal XLS detection, OLERead::read() appends the same sector data repeatedly until the PHP process exhausts memory. This is reachable from Reader\Xls::canRead() and therefore from automatic spreadsheet type detection. Applications that accept attacker-controlled spreadsheet uploads can suffer denial of service from a very small file. This issue has been fixed in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18 and 1.30.6.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-29
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 13 associated CPEs
Vendor Product Version / Range
phpoffice phpspreadsheet From 1.30.5 (inc) to 5.8.0 (inc)
phpoffice phpspreadsheet 1.30.6
phpoffice phpspreadsheet 2.1.18
phpoffice phpspreadsheet 2.4.7
phpoffice phpspreadsheet 3.10.7
phpoffice phpspreadsheet 5.8.1
phpspreadsheet phpspreadsheet From 1.30.0 (inc) to 5.8.0 (inc)
phpspreadsheet phpspreadsheet to 1.30.5 (inc)
phpspreadsheet phpspreadsheet 5.8.1
phpspreadsheet phpspreadsheet 3.10.7
phpspreadsheet phpspreadsheet 2.4.7
phpspreadsheet phpspreadsheet 2.1.18
phpspreadsheet phpspreadsheet 1.30.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects PhpSpreadsheet, a PHP library for reading and writing spreadsheet files. It involves a flaw in the OLE reader where sector chains from attacker-controlled XLS/OLE files are followed without detecting cycles or enforcing maximum chain length. A malformed .xls file can create a self-referential sector chain, causing the PHP process to exhaust memory during file detection or processing.

Detection Guidance

To detect this vulnerability, monitor for unusually high memory usage during file processing or crashes when handling XLS files. Check PhpSpreadsheet versions against affected ranges (1.30.5 to 5.8.0). Use commands like 'php -r "echo PHP_VERSION;"' to verify library versions.

Impact Analysis

Applications that accept untrusted spreadsheet uploads are vulnerable to denial of service from a very small malicious file. The PHP process can crash due to memory exhaustion, affecting web applications, queue workers, or document converters that handle these files.

Compliance Impact

This vulnerability primarily causes denial of service through memory exhaustion, which could disrupt services handling spreadsheet uploads. While not directly violating GDPR or HIPAA, such disruptions may impact availability requirements for systems processing personal or health data. Organizations must ensure robust input validation and patch management to maintain compliance with availability and security controls in these regulations.

Mitigation Strategies

Immediately upgrade PhpSpreadsheet to versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, or 1.30.6 or later. If upgrading is not possible, disable automatic spreadsheet type detection or block XLS file uploads until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59933. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart