<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 10:35:02 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-318055</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318055</link>
      <description>EUVD-2026-318055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318055</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40863</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40863</link>
      <description>&lt;p&gt;PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML XML reader (Reader\Xml) does not validate the ss:Index row attribute against the maximum allowed row count (AddressRange::MAX_ROW = 1,048,576). An attacker can craft a SpreadsheetML XML file with ss:Index=&amp;#34;999999999&amp;#34; on a &amp;lt;Row&amp;gt; element, which inflates the internal cachedHighestRow to ~1 billion. Any subsequent call to getRowIterator() without an explicit end row will attempt to iterate ~1 billion rows, causing CPU exhaustion and denial of service. This vulnerability is fixed in 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML XML reader (Reader\Xml) does not validate the ss:Index row attribute against the maximum allowed row count (AddressRange::MAX_ROW = 1,048,576). An attacker can craft a SpreadsheetML XML file with ss:Index=&amp;#34;999999999&amp;#34; on a &amp;lt;Row&amp;gt; element, which inflates the internal cachedHighestRow to ~1 billion. Any subsequent call to getRowIterator() without an explicit end row will attempt to iterate ~1 billion rows, causing CPU exhaustion and denial of service. This vulnerability is fixed in 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40863</guid>
    </item>
    <item>
      <title>GHSA-84wq-86v6-x5j6 — PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-84wq-86v6-x5j6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: phpoffice/phpspreadsheet&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The SpreadsheetML XML reader (`Reader\Xml`) does not validate the `ss:Index` row attribute against the maximum allowed row count (`AddressRange::MAX_ROW = 1,048,576`). An attacker can craft a SpreadsheetML XML file with `ss:Index=&amp;#34;999999999&amp;#34;` on a `&amp;lt;Row&amp;gt;` element, which inflates the internal `cachedHighestRow` to ~1 billion. Any subsequent call to `getRowIterator()` without an explicit end row will attempt to iterate ~1 billion rows, causing CPU exhaustion and denial of service.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;In `src/PhpSpreadsheet/Reader/Xml.php`, the `loadSpreadsheetFromFile` method processes `&amp;lt;Row&amp;gt;` elements:&lt;/p&gt;
&lt;p&gt;```php
// Xml.php:397-402
if (isset($row_ss[&amp;#39;Index&amp;#39;])) {
    $rowID = (int) $row_ss[&amp;#39;Index&amp;#39;]; // No validation against MAX_ROW
}
if (isset($row_ss[&amp;#39;Hidden&amp;#39;])) {
    $rowVisible = ((string) $row_ss[&amp;#39;Hidden&amp;#39;]) !== &amp;#39;1&amp;#39;;
    $spreadsheet-&amp;gt;getActiveSheet()-&amp;gt;getRowDimension($rowID)-&amp;gt;setVisible($rowVisible);
}
```&lt;/p&gt;
&lt;p&gt;The `$rowID` value read from `ss:Index` is cast to int with no upper bound check. It is then passed to `getRowDimension()`:&lt;/p&gt;
&lt;p&gt;```php
// Worksheet.php:1342-1351
public function getRowDimension(int $row): RowDimension
{
    if (!isset($this-&amp;gt;rowDimensions[$row])) {
        $this-&amp;gt;rowDimensions[$row] = new RowDimension($row);
        $this-&amp;gt;cachedHighestRow = max($this-&amp;gt;cachedHighestRow, $row);
    }
    return $this-&amp;gt;rowDimensions[$row];
}
```&lt;/p&gt;
&lt;p&gt;This inflates `cachedHighestRow` to the attacker-controlled value. Additionally, at line 412, `$cellRange = $columnID . $rowID`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: phpoffice/phpspreadsheet&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The SpreadsheetML XML reader (`Reader\Xml`) does not validate the `ss:Index` row attribute against the maximum allowed row count (`AddressRange::MAX_ROW = 1,048,576`). An attacker can craft a SpreadsheetML XML file with `ss:Index=&amp;#34;999999999&amp;#34;` on a `&amp;lt;Row&amp;gt;` element, which inflates the internal `cachedHighestRow` to ~1 billion. Any subsequent call to `getRowIterator()` without an explicit end row will attempt to iterate ~1 billion rows, causing CPU exhaustion and denial of service.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;In `src/PhpSpreadsheet/Reader/Xml.php`, the `loadSpreadsheetFromFile` method processes `&amp;lt;Row&amp;gt;` elements:&lt;/p&gt;
&lt;p&gt;```php
// Xml.php:397-402
if (isset($row_ss[&amp;#39;Index&amp;#39;])) {
    $rowID = (int) $row_ss[&amp;#39;Index&amp;#39;]; // No validation against MAX_ROW
}
if (isset($row_ss[&amp;#39;Hidden&amp;#39;])) {
    $rowVisible = ((string) $row_ss[&amp;#39;Hidden&amp;#39;]) !== &amp;#39;1&amp;#39;;
    $spreadsheet-&amp;gt;getActiveSheet()-&amp;gt;getRowDimension($rowID)-&amp;gt;setVisible($rowVisible);
}
```&lt;/p&gt;
&lt;p&gt;The `$rowID` value read from `ss:Index` is cast to int with no upper bound check. It is then passed to `getRowDimension()`:&lt;/p&gt;
&lt;p&gt;```php
// Worksheet.php:1342-1351
public function getRowDimension(int $row): RowDimension
{
    if (!isset($this-&amp;gt;rowDimensions[$row])) {
        $this-&amp;gt;rowDimensions[$row] = new RowDimension($row);
        $this-&amp;gt;cachedHighestRow = max($this-&amp;gt;cachedHighestRow, $row);
    }
    return $this-&amp;gt;rowDimensions[$row];
}
```&lt;/p&gt;
&lt;p&gt;This inflates `cachedHighestRow` to the attacker-controlled value. Additionally, at line 412, `$cellRange = $columnID . $rowID`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-84wq-86v6-x5j6</guid>
    </item>
  </channel>
</rss>
