phpoffice/phpspreadsheet is vulnerable to Denial of Service (DoS)
75
High Risk
The Gnumeric reader reads an attacker-supplied .gnumeric file and calls gzdecode() on gzip-compressed contents without enforcing a decompressed-size limit. A very small compressed file can expand to data larger than the PHP memory limit, crashing the process during canRead() before the file is validated or fully parsed. Applications that accept untrusted spreadsheet uploads can be forced into denial of service by a tiny decompression bomb. The fix bounds decompression output using a maximum length derived from the configured memory limit.
You are affected if you are using a version that falls within the vulnerable range and your application parses untrusted spreadsheet files.
phpoffice/phpspreadsheet is vulnerable to Denial of Service (DoS) in versions 4.0.0 - 5.8.0, 3.3.0 - 3.10.6, 2.2.0 - 2.4.6, 2.0.0 - 2.1.17 and 0.0.1 - 1.30.5.
Upgrade the phpoffice/phpspreadsheet library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant