SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityReceived

CVE-2026-79591

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

UnscoredEPSS 0.15%

Does this matter?

Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.

Description

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

CVSS
Not yet scored
EPSS
0.15% probability · 5th percentile
CISA KEV
Not listed
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.