Back to database
Track29Medium5.3VulnerabilityCVE-2026-107218No patch link observed

CVE-2026-107218 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.

Published Oct 7, 2026, 07:17 PM UTCIngested 1d agoSource NVD(cve-db)CVE-2026-107218

Description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with UTF-16 code-unit counts but slices a rune array using Unicode code-point counts. RIGHT reaches leftRight through CalcCellValue, where countUTF16String validates one unit but utf8.RuneCountInString supplies the slice index in another. When RIGHT evaluates supplementary-plane text with a requested character count between the rune count and UTF-16 code-unit count, the inconsistent units produce a negative rune-slice index, allowing an attacker to panic during formula evaluation. No fixed version is available as of this review.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
5.3

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

None

Confidentiality

I

None

Integrity

A

Low

Availability

Affected

Vendor
Go
Product
github.com/xuri/excelize/v2

Versions

  • pkg:golang/github.com/xuri/excelize/v2 >= 2.10.1, < 2.11.1-0.20260908032718-ecd99d761fe0

Stated as the source expressed them.