CVE-2026-59931
HIGH SEVERITYCVSS Score & Metrics
Base Score
7.7 / 10
Vulnerability Description
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
composer
Product
phpoffice/phpspreadsheet
External References
- https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-6hq5-7373-42rg
- https://github.com/PHPOffice/PhpSpreadsheet/commit/7ef7b25e8548a6ded79dac74e2e2c7acdac38d8d
- https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/1.30.6
- https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.1.18
- https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/2.4.7
- https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/3.10.7
- https://github.com/PHPOffice/PhpSpreadsheet/releases/tag/5.8.1
- https://github.com/advisories/GHSA-6hq5-7373-42rg
Discussion (0)
Add Comment
No comments yet. Be the first!