Medium severity5.5NVD Advisory· Published Jul 19, 2021· Updated Jun 17, 2026
CVE-2021-32012
CVE-2021-32012
Description
SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
xlsxnpm | < 0.17.0 | 0.17.0 |
org.webjars.npm:xlsxMaven | < 0.17.0 | 0.17.0 |
Affected products
6- SheetJS/SheetJS Prodescription
- ghsa-coords2 versions
< 0.17.0+ 1 more
- (no CPE)range: < 0.17.0
- (no CPE)range: < 0.17.0
- cpe:2.3:a:sheetjs_project:sheetjs_pro:*:*:*:*:*:node.js:*:*Range: <=0.16.9
- cpe:2.3:a:oracle:rest_data_services:*:*:*:*:*:*:*:*Range: <21.2.4
Patches
Vulnerability mechanics
References
7- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party AdvisoryWEB
- floqast.com/engineering-blog/post/fuzzing-and-parsing-securely/nvdThird Party Advisory
- github.com/advisories/GHSA-3x9f-74h4-2fqrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-32012ghsaADVISORY
- sheetjs.com/pronvdProductVendor AdvisoryWEB
- www.npmjs.com/package/xlsx/v/0.17.0nvdProductThird Party AdvisoryWEB
- floqast.com/engineering-blog/post/fuzzing-and-parsing-securelyghsaWEB
News mentions
0No linked articles in our index yet.