Skip to main content
EPSS 0.4%top 69%

CVE-2026-59931: CWE-918: Server-Side Request Forgery (SSRF) in PHPOffice PhpSpreadsheet

0
High
VulnerabilityCVE-2026-59931cvecve-2026-59931cwe-918
Published: 07/28/2026 (07/28/2026, 17:27:27 UTC)
Source: CVE Database V5
Vendor/Project: PHPOffice
Product: PhpSpreadsheet

Description

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the WEBSERVICE() domain whitelist can be bypassed via an HTTP redirect (SSRF). In Calculation/Web/Service.php, the webService() method validates a URL's host against the whitelist set via Spreadsheet::setDomainWhiteList(), then fetches content with file_get_contents($url, false, $ctx); because PHP's HTTP stream wrapper follows 301/302 redirects automatically (up to 20 hops) and the redirect target is never re-validated, an attacker who can trigger a redirect from a whitelisted domain can reach arbitrary URLs, including internal addresses. An attacker able to upload XLSX files to an application that uses setDomainWhiteList() and getCalculatedValue() can achieve a full-read SSRF, returning up to 32,767 bytes of the response body as a cell's calculated value, which enables exfiltration of cloud metadata (AWS/GCP/Azure credentials via http://169.254.169.254/), access to internal-only services, and internal port scanning (the port is not validated). This issue has been fixed in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6.

CVSS v3.1

Score 7.7high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected software

PHPOffice

PhpSpreadsheet

Affected versions
>=4.0.0 <5.8.1>=3.3.0 <3.10.7>=2.2.0 <2.4.7>=2.0.0 <2.1.18<1.30.6

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/29/2026, 15:52:38 UTC

Technical Analysis

PhpSpreadsheet's webService() method validates URLs against a domain whitelist before fetching content. However, because PHP's HTTP stream wrapper automatically follows HTTP 301/302 redirects without re-validating the redirect target, an attacker can bypass the whitelist by triggering redirects from whitelisted domains to arbitrary internal or external URLs. This SSRF vulnerability allows an attacker who can upload XLSX files and invoke getCalculatedValue() to read up to 32,767 bytes from arbitrary URLs, including cloud metadata endpoints (e.g., http://169.254.169.254/), internal services, and ports. The vulnerability affects multiple version ranges up to 5.8.0 and has been fixed in subsequent patch releases.

Potential Impact

An attacker able to upload malicious XLSX files can exploit this SSRF vulnerability to read sensitive internal resources and cloud metadata service endpoints, potentially exposing cloud credentials and enabling internal network reconnaissance. The vulnerability does not impact integrity or availability but has a high confidentiality impact. This can lead to unauthorized access to sensitive information and further compromise of internal systems.

Mitigation Recommendations

A fix is available in PhpSpreadsheet versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6. Users should upgrade to these or later versions to remediate the vulnerability. Since this is a cloud service, the vendor manages remediation for the cloud-hosted service; users should verify with the vendor that their environment is updated accordingly. Until patched, avoid processing untrusted XLSX files that use the WEBSERVICE() function with domain whitelisting.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-07-07T18:20:06.126Z
Cvss Version
3.1
State
PUBLISHED
Is Cloud Service
true

Threat ID: 6a68ec699c2644c7f8faaddb

Added to database: 07/28/2026, 17:52:41 UTC

Last enriched: 07/29/2026, 15:52:38 UTC

Last updated: 09/10/2026, 20:01:12 UTC

Views: 75

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses