CVE-2026-97222: Gnome Gnumeric
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash.
Affected products
- Gnome Gnumeric: from 1.11.0
Published 2026-09-25. Last modified 2026-09-30.