PatchSiren cyber security CVE debrief
CVE-2026-79591 libxls CVE debrief
A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index. This CVE record was published on 2026-09-10T21:17:46.933Z and has not been modified since then. The NVD entry is currently 7.8 HIGH. The vulnerability affects systems or applications using the libxls library, requiring verification of library version and assessment of exposure in relevant deployment contexts. Defenders should prioritize verifying the libxls library version and assessing exposure in relevant deployment contexts.
- Vendor
- libxls
- Product
- libxls
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-15
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-15
Who should care
Defenders responsible for systems or applications using the libxls library should assess exposure and prioritize verification. This includes operators, platform administrators, vulnerability management teams, and security teams. They should verify the libxls library version in use, assess exposure in relevant deployment contexts, and consider compensating controls or monitoring.
Why it matters
CVE-2026-79591 is a heap-buffer-overflow and use-after-free vulnerability in libxls 1.6.3, requiring verification of library version and assessment of exposure in relevant deployment contexts.
- Verification of libxls library version is required to determine exposure
- Assessment of deployment contexts is necessary to determine potential impact
- Compensating controls or monitoring may be necessary to mitigate potential consequences
Technical summary
The xls_getCSS() function in libxls 1.6.3 has a heap-buffer-overflow and use-after-free vulnerability due to insufficient validation of a file-controlled font index. This vulnerability affects systems or applications using the libxls library. The vulnerability requires verification of library version and assessment of exposure in relevant deployment contexts. The CVE record and NVD detail page provide information on the vulnerability, but further verification is needed to determine the affected scope and remediation.
Defensive priority
Defenders should prioritize verifying the libxls library version and assessing exposure in relevant deployment contexts.
Recommended defensive actions
- Verify the libxls library version in use
- Assess exposure in relevant deployment contexts
- Consider compensating controls or monitoring
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, but further verification is needed to determine the affected scope and remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-79591 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-79591
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-79591 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79591
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/libxls/libxls/issues/161
-
Source reference
Unverified legacy reference
URL: https://github.com/libxls/libxls/pull/164/changes/902c8f9b13710c3a13b6232fb86626c5c729402c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.