CVE-2026-107218 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.
Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with UTF-16 code-unit counts but slices a rune array using Unicode code-point counts. RIGHT reaches leftRight through CalcCellValue, where countUTF16String validates one unit but utf8.RuneCountInString supplies the slice index in another. When RIGHT evaluates supplementary-plane text with a requested character count between the rune count and UTF-16 code-unit count, the inconsistent units produce a negative rune-slice index, allowing an attacker to panic during formula evaluation. No fixed version is available as of this review.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
None
Confidentiality
I
None
Integrity
A
Low
Availability
Affected
- Vendor
- Go
- Product
- github.com/xuri/excelize/v2
Versions
- pkg:golang/github.com/xuri/excelize/v2 >= 2.10.1, < 2.11.1-0.20260908032718-ecd99d761fe0
Stated as the source expressed them.
References
- advisory[email protected]https://github.com/qax-os/excelize/commit/ecd99d761fe0489f1ed308e2f7dc2e0502d1a396
- advisory[email protected]https://github.com/qax-os/excelize/pull/2390
- advisory[email protected]https://github.com/qax-os/excelize/security/advisories/GHSA-8jjq-8j9w-m2v6
- advisoryOSV GHSA-8jjq-8j9w-m2v6https://osv.dev/vulnerability/GHSA-8jjq-8j9w-m2v6
- vendorOSV packagehttps://github.com/qax-os/excelize
Related threats
same CWE or vendorCVE-2026-107737 — SumatraPDF is a multi-format reader for Windows.
CVE-2026-107737 · 3h ago
CVE-2026-107386 — amqp091-go is a Go AMQP 0.9.1 client.
CVE-2026-107386 · 7h ago
CVE-2026-107325 — Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bs…
CVE-2026-107325 · 7h ago
Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor
OSV · 8h ago
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
OSV · 8h ago
Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion
OSV · 8h ago