CVE-2026-26825

Source
https://cve.org/CVERecord?id=CVE-2026-26825
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26825.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-26825
Downstream
Published
2026-06-03T00:00:00Z
Modified
2026-09-25T08:11:22Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read). The flaw is detectable with MemorySanitizer (MSAN) and can lead to undefined behavior, incorrect parsing logic, or potential information disclosure.

Database specific
{
    "cna_assigner":  "mitre",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26825.json"
}
References

Affected packages

Git / github.com/libxls/libxls

Affected ranges

Type
GIT
Repo
https://github.com/libxls/libxls
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:libxls_project:libxls:1.6.3:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "1.6.3"
        },
        {
            "last_affected":  "1.6.3"
        }
    ],
    "source":  [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.6.3
v1.*
v1.6.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26825.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "264078684148903378622940615105383007470",
            "length":  2032
        },
        "id":  "CVE-2026-26825-0751d43a",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
        "target":  {
            "file":  "src/ole.c",
            "function":  "ole2_read_header"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "140135237475174582087241996969871704747",
            "length":  943
        },
        "id":  "CVE-2026-26825-1dbd1b5f",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
        "target":  {
            "file":  "src/ole.c",
            "function":  "read_MSAT"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "218525061500905510133011887485141753690",
            "length":  130
        },
        "id":  "CVE-2026-26825-77d35704",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
        "target":  {
            "file":  "src/ole.c",
            "function":  "ole_malloc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "296689250788399748227633831580724208028",
                "149946746295500794092917765559369311348",
                "47679858712167494421244073889815843693",
                "234241646671746529850815561971632955095",
                "152057817600294929727590345940714593929",
                "317455059814954984630555638441908228406",
                "287789177408259458779660684345033557494",
                "230364032453286730726909371859301353573",
                "315676220791700766539480923143937882649",
                "310204014449606216286705283475928351716",
                "299116124785706865602948143650187748097",
                "330481530641008190552496565516381875244",
                "20987924295628701520786847067787259078",
                "322822460734308770949133897291006238162",
                "42810552882531259432343970828057290188",
                "142820936036142349090952564956980111029",
                "219178953299287403384436068900444754978",
                "178787641231754583288691167305500978831",
                "25170487468147185558321804607884489318",
                "18604746064334544832977582618783189282"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-26825-aeb0d7a9",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
        "target":  {
            "file":  "src/ole.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "320795350469443913802810492891603988577",
            "length":  1042
        },
        "id":  "CVE-2026-26825-b15a361a",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
        "target":  {
            "file":  "src/ole.c",
            "function":  "read_MSAT_trailer"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "212851827028361751074446939725073589627",
            "length":  3628
        },
        "id":  "CVE-2026-26825-e3b02ba0",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/libxls/libxls/commit/9adf88f4e3b304e397f70ac189e70776edb6d5a3",
        "target":  {
            "file":  "src/ole.c",
            "function":  "ole2_read_body"
        }
    }
]
vanir_signatures_modified
"2026-09-25T08:11:22Z"