{
  "ticket_id": "CVE-2026-34084",
  "source": "cve",
  "cve_id": "CVE-2026-34084",
  "advisory_id": "GHSA-q4q6-r8wh-5cgh",
  "html_url": "https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-q4q6-r8wh-5cgh",
  "references": [
    "https://github.com/PHPOffice/PhpSpreadsheet/security/advisories/GHSA-q4q6-r8wh-5cgh",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-34084",
    "https://github.com/PHPOffice/PhpSpreadsheet"
  ],
  "severity": "critical",
  "cwe": ["CWE-502", "CWE-918"],
  "cvss": {
    "nvd_v3_1_base_score": 9.2
  },
  "labels": ["security", "ssrf", "deserialization", "phpspreadsheet", "packagist"],
  "state": "published"
}
