Executive brief
PhpSpreadsheet is a widely used PHP library for reading and writing spreadsheet files, often used by web applications to process user-uploaded data. A vulnerability in how it handles XLSX files allows an attacker to provide a specially crafted, very small file that forces the server to perform billions of unnecessary calculations. This can lead to a denial-of-service (DoS) condition, where the server's CPU resources are exhausted, making the application unresponsive to legitimate users.
Technical details
A CPU denial-of-service vulnerability exists in the PhpSpreadsheet XLSX reader's ColumnAndRowAttributes::readRowAttributes() method. The library reads row numbers from XML attributes without validating them against the maximum row limit (1,048,576). An attacker can craft a minimal XLSX file containing a row attribute with an extremely high value (e.g., 999,999,999), which inflates the 'cachedHighestRow' property. Subsequent row iterations using getRowIterator() or loops bounded by getHighestRow() will attempt to execute approximately 1 billion cycles, exhausting CPU resources. The vulnerability is fixed in versions 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0 by adding bounds checking to the row index.
Affected products
- PHPOffice phpoffice/phpspreadsheet < 1.30.4, >= 2.0.0, < 2.1.16, >= 2.2.0, < 2.4.5, >= 3.3.0, < 3.10.5, >= 4.0.0, < 5.7.0
Timeline
- 2026-04-28: advisory: GitHub security advisory published by maintainers
- 2026-05-12: disclosed: NVD publication date