libxls vulnerabilities
CVEs whose affected-version data names the libxls package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-26825Medium· 5.3A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files
A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap memory originating from the OLE layer (ole2_read).…
▾ Sunlitlibxls_project · libxlsEPSS 0.21%via NVD
CVE-2026-26824Medium· 6.5PoClibxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser
libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) in read_MSAT() is not fully initialized before being consumed b…
▾ Twilightlibxls_project · libxlsEPSS 0.23%via NVD