{"id":"CVE-2026-97222","published":"2026-09-25T14:17:25.580","lastModified":"2026-09-25T17:17:20.773","description":"A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash.","cvssScore":5.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwes":["CWE-416"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-97222","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2541397","tags":[]},{"url":"https://gitlab.gnome.org/GNOME/gnumeric/-/issues/897","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}