CVE-2026-59931: CWE-918: Server-Side Request Forgery (SSRF) in PHPOffice PhpSpreadsheet
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the WEBSERVICE() domain whitelist can be bypassed via an HTTP redirect (SSRF). In Calculation/Web/Service.php, the webService() method validates a URL's host against the whitelist set via Spreadsheet::setDomainWhiteList(), then fetches content with file_get_contents($url, false, $ctx); because PHP's HTTP stream wrapper follows 301/302 redirects automatically (up to 20 hops) and the redirect target is never re-validated, an attacker who can trigger a redirect from a whitelisted domain can reach arbitrary URLs, including internal addresses. An attacker able to upload XLSX files to an application that uses setDomainWhiteList() and getCalculatedValue() can achieve a full-read SSRF, returning up to 32,767 bytes of the response body as a cell's calculated value, which enables exfiltration of cloud metadata (AWS/GCP/Azure credentials via http://169.254.169.254/), access to internal-only services, and internal port scanning (the port is not validated). This issue has been fixed in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6.
AI Analysis
Technical Summary
PhpSpreadsheet's webService() method validates URLs against a domain whitelist before fetching content. However, because PHP's HTTP stream wrapper automatically follows HTTP 301/302 redirects without re-validating the redirect target, an attacker can bypass the whitelist by triggering redirects from whitelisted domains to arbitrary internal or external URLs. This SSRF vulnerability allows an attacker who can upload XLSX files and invoke getCalculatedValue() to read up to 32,767 bytes from arbitrary URLs, including cloud metadata endpoints (e.g., http://169.254.169.254/), internal services, and ports. The vulnerability affects multiple version ranges up to 5.8.0 and has been fixed in subsequent patch releases.
Potential Impact
An attacker able to upload malicious XLSX files can exploit this SSRF vulnerability to read sensitive internal resources and cloud metadata service endpoints, potentially exposing cloud credentials and enabling internal network reconnaissance. The vulnerability does not impact integrity or availability but has a high confidentiality impact. This can lead to unauthorized access to sensitive information and further compromise of internal systems.
Mitigation Recommendations
A fix is available in PhpSpreadsheet versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6. Users should upgrade to these or later versions to remediate the vulnerability. Since this is a cloud service, the vendor manages remediation for the cloud-hosted service; users should verify with the vendor that their environment is updated accordingly. Until patched, avoid processing untrusted XLSX files that use the WEBSERVICE() function with domain whitelisting.
CVE-2026-59931: CWE-918: Server-Side Request Forgery (SSRF) in PHPOffice PhpSpreadsheet
Description
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the WEBSERVICE() domain whitelist can be bypassed via an HTTP redirect (SSRF). In Calculation/Web/Service.php, the webService() method validates a URL's host against the whitelist set via Spreadsheet::setDomainWhiteList(), then fetches content with file_get_contents($url, false, $ctx); because PHP's HTTP stream wrapper follows 301/302 redirects automatically (up to 20 hops) and the redirect target is never re-validated, an attacker who can trigger a redirect from a whitelisted domain can reach arbitrary URLs, including internal addresses. An attacker able to upload XLSX files to an application that uses setDomainWhiteList() and getCalculatedValue() can achieve a full-read SSRF, returning up to 32,767 bytes of the response body as a cell's calculated value, which enables exfiltration of cloud metadata (AWS/GCP/Azure credentials via http://169.254.169.254/), access to internal-only services, and internal port scanning (the port is not validated). This issue has been fixed in versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6.
CVSS v3.1
Score 7.7high
Affected software
PHPOffice
PhpSpreadsheet
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
PhpSpreadsheet's webService() method validates URLs against a domain whitelist before fetching content. However, because PHP's HTTP stream wrapper automatically follows HTTP 301/302 redirects without re-validating the redirect target, an attacker can bypass the whitelist by triggering redirects from whitelisted domains to arbitrary internal or external URLs. This SSRF vulnerability allows an attacker who can upload XLSX files and invoke getCalculatedValue() to read up to 32,767 bytes from arbitrary URLs, including cloud metadata endpoints (e.g., http://169.254.169.254/), internal services, and ports. The vulnerability affects multiple version ranges up to 5.8.0 and has been fixed in subsequent patch releases.
Potential Impact
An attacker able to upload malicious XLSX files can exploit this SSRF vulnerability to read sensitive internal resources and cloud metadata service endpoints, potentially exposing cloud credentials and enabling internal network reconnaissance. The vulnerability does not impact integrity or availability but has a high confidentiality impact. This can lead to unauthorized access to sensitive information and further compromise of internal systems.
Mitigation Recommendations
A fix is available in PhpSpreadsheet versions 5.8.1, 3.10.7, 2.4.7, 2.1.18, and 1.30.6. Users should upgrade to these or later versions to remediate the vulnerability. Since this is a cloud service, the vendor manages remediation for the cloud-hosted service; users should verify with the vendor that their environment is updated accordingly. Until patched, avoid processing untrusted XLSX files that use the WEBSERVICE() function with domain whitelisting.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-07T18:20:06.126Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Is Cloud Service
- true
Threat ID: 6a68ec699c2644c7f8faaddb
Added to database: 07/28/2026, 17:52:41 UTC
Last enriched: 07/29/2026, 15:52:38 UTC
Last updated: 09/10/2026, 20:01:12 UTC
Views: 75
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.