Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-59931— PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist

CVSS 7.7 · High EPSS 0.53% · P42

Affected Version Matrix 5

VendorProductVersion RangeStatus
PHPOfficePhpSpreadsheet>= 4.0.0, < 5.8.1affected
>= 3.3.0, < 3.10.7affected
>= 2.2.0, < 2.4.7affected
>= 2.0.0, < 2.1.18affected
< 1.30.6affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-59931

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
Source: CVE Program / CVE List V5
Vulnerability Description
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the WEBSERVICE() domain whitelist can be bypassed via an HTTP redirect (SSRF). In Calculation/Web/Service.php, the webService() method validates a URL's host against the whitelist set via Spreadsheet::setDomainWhiteList(), then fetches content with file_get_contents($url, false, $ctx); because PHP's HTTP stream wrapper follows 301/302 redirects automatically (up to 20 hops) and the redirect target is never re-validated, an attacker who can trigger a redirect from a whitelisted domain can reach arbitrary URLs, including internal addresses. An attacker able to upload XLSX files to an application that uses setDomainWhiteList() and getCalculatedValue() can achieve a full-read SSRF, returning up to 32,767 bytes of the response body as a cell's calculated value, which enables exfiltration of cloud metadata (AWS/GCP/Azure credentials via http://169.254.169.254/), access to internal-only services, and internal port scanning (the port is not validated). This issue has been fixed in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5
Vulnerability Title
PHPOffice PhpSpreadsheet 服务端请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PHPOffice PhpSpreadsheet是PHPOffice组织开源的一款用于读取和写入电子表格文件的PHP库。 PHPOffice PhpSpreadsheet 1.30.6之前版本、2.0.0版本至2.1.18之前版本、2.2.0版本至2.4.7之前版本、3.3.0版本至3.10.7之前版本和4.0.0版本至5.8.1之前版本存在服务端请求伪造漏洞,该漏洞源于WEBSERVICE()域白名单可通过HTTP重定向绕过,导致服务端请求伪造(SSRF),攻击者可上传XLSX文件触发重定向,从而访问任
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
PHPOfficePhpSpreadsheet >= 4.0.0, < 5.8.1 -

II. Public POCs for CVE-2026-59931

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 13871 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-59931

登录查看更多情报信息。

Patches & Fixes for CVE-2026-59931 (1)

Vendor Advisories for CVE-2026-59931 (1)

Vendor Pages for CVE-2026-59931 (5)

Same Patch Batch · PHPOffice · 2026-07-28 · 3 CVEs total

CVE-2026-599327.5 HIGHPhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
CVE-2026-599337.5 HIGHPhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion

IV. Related Vulnerabilities

V. Comments for CVE-2026-59931

No comments yet


Leave a comment