A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26825.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26825.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "264078684148903378622940615105383007470",
"length": 2032
},
"id": "CVE-2026-26825-0751d43a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
"target": {
"file": "src/ole.c",
"function": "ole2_read_header"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "140135237475174582087241996969871704747",
"length": 943
},
"id": "CVE-2026-26825-1dbd1b5f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
"target": {
"file": "src/ole.c",
"function": "read_MSAT"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "218525061500905510133011887485141753690",
"length": 130
},
"id": "CVE-2026-26825-77d35704",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
"target": {
"file": "src/ole.c",
"function": "ole_malloc"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"296689250788399748227633831580724208028",
"149946746295500794092917765559369311348",
"47679858712167494421244073889815843693",
"234241646671746529850815561971632955095",
"152057817600294929727590345940714593929",
"317455059814954984630555638441908228406",
"287789177408259458779660684345033557494",
"230364032453286730726909371859301353573",
"315676220791700766539480923143937882649",
"310204014449606216286705283475928351716",
"299116124785706865602948143650187748097",
"330481530641008190552496565516381875244",
"20987924295628701520786847067787259078",
"322822460734308770949133897291006238162",
"42810552882531259432343970828057290188",
"142820936036142349090952564956980111029",
"219178953299287403384436068900444754978",
"178787641231754583288691167305500978831",
"25170487468147185558321804607884489318",
"18604746064334544832977582618783189282"
],
"threshold": 0.9
},
"id": "CVE-2026-26825-aeb0d7a9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
"target": {
"file": "src/ole.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "320795350469443913802810492891603988577",
"length": 1042
},
"id": "CVE-2026-26825-b15a361a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
"target": {
"file": "src/ole.c",
"function": "read_MSAT_trailer"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "212851827028361751074446939725073589627",
"length": 3628
},
"id": "CVE-2026-26825-e3b02ba0",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
"target": {
"file": "src/ole.c",
"function": "ole2_read_body"
}
}
]
"2026-09-25T08:11:22Z"