CVE-2026-107217 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.
Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing name VGWQHXLSDVIKWV, after which checkSheetR0 and xlsxWorksheet.checkRow use the wrapped column value as an index. When a crafted worksheet uses an overflowing column name in a row normalized by checkSheetR0 or checkRow, the wrapped zero column becomes a negative slice index during worksheet normalization, allowing an attacker to panic and terminate the calling process. No fixed version is available as of this review.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
None
Confidentiality
I
None
Integrity
A
High
Availability
Affected
- Vendor
- Go
- Product
- github.com/xuri/excelize/v2
Versions
- pkg:golang/github.com/xuri/excelize/v2 >= 2.0.0, < 2.11.1-0.20260910071107-696050fbf14e
- pkg:golang/github.com/xuri/excelize >= 1.1.0, <= 1.4.1
Stated as the source expressed them.
References
- advisory[email protected]https://github.com/qax-os/excelize/commit/696050fbf14e74e96a58eef2b16aaf72f381a6a8
- advisory[email protected]https://github.com/qax-os/excelize/pull/2394
- advisory134c704f-9b21-4f2e-91b3-4a467353bcc0https://github.com/qax-os/excelize/security/advisories/GHSA-c85p-xxjj-2r75
- advisoryOSV GHSA-c85p-xxjj-2r75https://osv.dev/vulnerability/GHSA-c85p-xxjj-2r75
- vendorOSV packagehttps://github.com/qax-os/excelize
Related threats
same CWE or vendorCVE-2026-107386 — amqp091-go is a Go AMQP 0.9.1 client.
CVE-2026-107386 · 5h ago
CVE-2026-107325 — Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bs…
CVE-2026-107325 · 5h ago
CVE-2026-107324 — An integer overflow in BSON value-length handling in the MongoDB Go Driver can cause a runtime panic when an application validates or accesses a ma…
CVE-2026-107324 · 5h ago
Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor
OSV · 7h ago
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
OSV · 7h ago
Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion
OSV · 7h ago