PKSA-dqzt-yst9-1w9y Security Advisory
-
[HIGH] PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
PKSA-dqzt-yst9-1w9y CVE-2026-59931 GHSA-6hq5-7373-42rg
Affected package: phpoffice/phpspreadsheet
Affected version: <=1.30.5|>=2.0.0,<=2.1.17|>=2.2.0,<=2.4.6|>=3.3.0,<=3.10.6|>=4.0.0,<=5.8.0
Reported by:
GitHub