CVE-2024-22368: Tozt Spreadsheet::parsexlsx
Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.
The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation does not have appropriate constraints on merged cells.
Affected products
- Tozt Spreadsheet::parsexlsx: before 0.28 (fixed in 0.28)
Published 2024-01-09. Last modified 2026-06-17.