CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59931

highCVSS 7.7covered by 2 sourcesfirst seen 2026-07-23
Summary The domain whitelist introduced in PhpSpreadsheet 5.4.0 for the WEBSERVICE() formula function can be bypassed via HTTP redirect. The whitelist validates only the initial URL's hostname, but file_get_contents() follows 302/301 redirects by default without re-validating the redirect target against the whitelist. This allows an attacker to reach internal services through a whitelisted domain that issues an HTTP redirect. Details In Calculation/Web/Service.php, the webService() method validates the URL's host against a domain whitelist set via Spreadsheet::setDomainWhiteList(). If the host passes validation, the method calls file_get_contents($url, false, $ctx) to fetch the content. The stream context does not disable redirect following: $ctxArray = [ 'http' => [ 'user_agent' => 'Mozilla/5.0 ...', // follow_location defaults to true // max_redirects defaults to 20 ], ]; PHP's HTTP stream wrapper follows redirects automatically (up to 20 hops by default). The redirect target URL is not re-validated against the domain whitelist. An attacker who can trigger a 302 redirect from a whitelisted domain can redirect the request to any arbitrary URL, including internal network addresses. Vulnerable code (Calculation/Web/Service.php): // Whitelist check — runs ONCE on the initial URL $domainWhiteList = $cell?->getWorksheet()->getParent()?->getDomainWhiteList() ?? []; $host = $parsed['host'] ?? ''; if (!in_array($host, $domainWhiteList, true)) { return ($cell === null) ? null : Functions::NOT_YET_IMPLEMENTED; } // HTTP request — follows redirects to ANY destination $ctx = stream_context_create($ctxArray); $output = @file_get_contents($url, false, $ctx); Additionally, the whitelist check uses only the hostname from parse_url(), ignoring the port. This means whitelisting example.com permits access to all ports on that host. PoC Prerequisites: - Application uses PhpSpreadsheet >= 5.4.0 - Application calls $spreadsheet->setDomainWhiteList([...]) with at least one do

⚡ Watch CVE-2026-59931

Get an email if CVE-2026-59931 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-59931

CVE.org record

Embed the live status

CVE-2026-59931 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-59931 status](https://www.csirts.com/badge/CVE-2026-59931)](https://www.csirts.com/cve/CVE-2026-59931)