๐Ÿ” CVE Alert

CVE-2026-59931

HIGH 7.7

PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the WEBSERVICE() domain whitelist can be bypassed via an HTTP redirect (SSRF). In Calculation/Web/Service.php, the webService() method validates a URL's host against the whitelist set via Spreadsheet::setDomainWhiteList(), then fetches content with file_get_contents($url, false, $ctx); because PHP's HTTP stream wrapper follows 301/302 redirects automatically (up to 20 hops) and the redirect target is never re-validated, an attacker who can trigger a redirect from a whitelisted domain can reach arbitrary URLs, including internal addresses. An attacker able to upload XLSX files to an application that uses setDomainWhiteList() and getCalculatedValue() can achieve a full-read SSRF, returning up to 32,767 bytes of the response body as a cell's calculated value, which enables exfiltration of cloud metadata (AWS/GCP/Azure credentials via http://169.254.169.254/), access to internal-only services, and internal port scanning (the port is not validated). This issue has been fixed in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6.

CWE CWE-918
Vendor phpoffice
Product phpspreadsheet
Published Jul 28, 2026
Last Updated Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for phpoffice phpspreadsheet

Be the first to know when new high vulnerabilities affecting phpoffice phpspreadsheet are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

PHPOffice / PhpSpreadsheet
>= 4.0.0, < 5.8.1 >= 3.3.0, < 3.10.7 >= 2.2.0, < 2.4.7 >= 2.0.0, < 2.1.18 < 1.30.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-6hq5-7373-42rg github.com: https://github.com/PHPOffice/PhpSpreadsheet/commit/7ef7b25e8548a6ded79dac74e2e2c7acdac38d8d github.com: https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/1.30.6 github.com: https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.1.18 github.com: https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.4.7 github.com: https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/3.10.7 github.com: https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/5.8.1