What is CVE-2026-59931?
CVE-2026-59931 is an SSRF vulnerability in the PhpSpreadsheet library where the WEBSERVICE() domain whitelist can be bypassed via an HTTP redirect. It affects all versions up to 1.30.5, and versions from 2.0.0 through 5.8.0. Users should immediately upgrade to the latest patched version and review whitelist configurations.
Azərbaycanca: CVE-2026-59931, PhpSpreadsheet kitabxanasında WEBSERVICE() funksiyasının domen whitelist-inin HTTP redirect vasitəsilə yan keçilməsinə imkan verən SSRF zəifliyidir. Bu, 1.30.5-ə qədər bütün versiyalar və 2.0.0-dan 5.8.0-a qədər olan versiyalara təsir edir. İstifadəçilər dərhal ən son təhlükəsizlik yeniləməsinə keçməli və whitelist konfiqurasiyasını yoxlamalıdır.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What vulnerability does CVE-2026-59931 cause in PhpSpreadsheet?
This CVE is an SSRF vulnerability where the domain whitelist of the WEBSERVICE() function can be bypassed via an HTTP redirect.
Which PhpSpreadsheet versions are affected by CVE-2026-59931?
All versions up to 1.30.5, and versions from 2.0.0 through 5.8.0 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.