phpoffice/phpspreadsheet is vulnerable to Denial of Service (DoS)
75
High Risk
The OLE reader used by the XLS reader follows sector chains from attacker-controlled OLE metadata without detecting cycles or bounding the chain length. A tiny malformed .xls/OLE file can point the small-block depot sector chain back to itself, causing the reader to append the same sector data repeatedly until memory is exhausted. This is reachable during automatic file-type detection in canRead(), so untrusted uploads can trigger denial of service. The fix tracks visited blocks and throws a reader exception when a loop is detected.
You are affected if you are using a version that falls within the vulnerable range and your application parses untrusted spreadsheet files.
phpoffice/phpspreadsheet is vulnerable to Denial of Service (DoS) in versions 4.0.0 - 5.8.0, 3.3.0 - 3.10.6, 2.2.0 - 2.4.6, 2.0.0 - 2.1.17 and 0.0.1 - 1.30.5.
Upgrade the phpoffice/phpspreadsheet library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant