
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-59931 is a Server-Side Request Forgery (SSRF) vulnerability in PHPOffice/PhpSpreadsheet that allows authenticated attackers to bypass the domain whitelist introduced in version 5.4.0 for the WEBSERVICE() formula function via HTTP redirect. The whitelist validates only the initial URL's hostname, but PHP's file_get_contents() follows 301/302 redirects by default without re-validating the redirect target, enabling access to arbitrary internal services. Affected versions span multiple release branches: <= 1.30.5, >= 2.0.0, <= 2.1.17, >= 2.2.0, <= 2.4.6, >= 3.3.0, <= 3.10.6, and >= 4.0.0, <= 5.8.0. The vulnerability was published on July 19, 2026, and carries a CVSS v3.1 base score of 7.7 (High) (GitHub Advisory).
The root cause is CWE-918 (Server-Side Request Forgery), located in Calculation/Web/Service.php within the webService() method. The method validates the initial URL's hostname against a domain whitelist via Spreadsheet::setDomainWhiteList(), then calls file_get_contents($url, false, $ctx) using a stream context that does not set follow_location => false, meaning PHP's HTTP stream wrapper follows up to 20 redirect hops by default without re-checking each hop's destination against the whitelist. An attacker exploiting this must have the ability to upload or supply XLSX files to an application that calls setDomainWhiteList() and getCalculatedValue(), and must be able to trigger a redirect from a whitelisted domain (e.g., via an open redirect endpoint, an attacker-controlled whitelisted domain, or DNS rebinding). Additionally, the whitelist check uses only the hostname from parse_url() and ignores the port, enabling port scanning of whitelisted hosts (GitHub Advisory, Patch Commit).
Successful exploitation enables a full-read SSRF, returning up to 32,767 bytes of the HTTP response body as the cell's calculated value, directly exposing sensitive internal data to the attacker. Attackers can exfiltrate cloud instance metadata (AWS/GCP/Azure credentials via http://169.254.169.254/), access internal services not exposed to the internet, and perform port scanning of internal networks through any whitelisted hostname. The confidentiality impact is high, with no integrity or availability impact; however, leaked cloud credentials could enable lateral movement and further compromise of cloud infrastructure (GitHub Advisory).
setDomainWhiteList() and getCalculatedValue() (versions 1.x through 5.8.0).WEBSERVICE() formula targeting the redirect URL on the whitelisted domain, e.g.:=_xlfn.WEBSERVICE("http://whitelisted-domain.com/redirect?url=http://169.254.169.254/latest/meta-data/")getCalculatedValue(), which validates whitelisted-domain.com against the whitelist (passes), then calls file_get_contents(), which follows the 302 redirect to the internal target without re-validation.169.254.169.254) or unexpected internal IP ranges; HTTP requests to whitelisted domains immediately followed by redirect chains to internal addresses observable in proxy/WAF logs.file_get_contents with internal or link-local IP addresses as targets.WEBSERVICE or _xlfn.WEBSERVICE formulas referencing external or redirect URLs in upload directories.169.254.169.254:80) (GitHub Advisory).Patched versions are available across all affected branches: 1.30.6, 2.1.18, 2.4.7, 3.10.7, and 5.8.1. The fix sets follow_location => 0 in the PHP stream context used by file_get_contents(), preventing automatic redirect following. If upgrading is not immediately possible, a workaround is to disable the WEBSERVICE() formula entirely or avoid calling getCalculatedValue() on untrusted XLSX files. If redirect support is required, implement manual redirect following that re-validates each hop's hostname (and port) against the domain whitelist (GitHub Advisory, Patch Commit).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"