Back to database
Schedule36Medium6.5VulnerabilityCVE-2026-107220No patch link observed

CVE-2026-107220 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.

Published Oct 7, 2026, 07:17 PM UTCIngested 1d agoSource NVD(cve-db)CVE-2026-107220

Description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.1 to 2.11.0, mergeCellsParser leaves the cached rectangle empty for an empty mergeCell ref and then passes that empty slice to cellInRange without a length check. GetCellValue reaches mergeCellsParser, which passes an empty rectangle derived from the mergeCell ref attribute into cellInRange. When a crafted worksheet contains an empty mergeCell ref and a non-streaming cell API reads the worksheet, cellInRange indexes four positions in an empty slice, allowing an attacker to panic on the first affected cell operation. No fixed version is available as of this review.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
6.5

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

Required

User Interaction

S

Unchanged

Scope

C

None

Confidentiality

I

None

Integrity

A

High

Availability

Affected

Vendor
Go
Product
github.com/xuri/excelize/v2

Versions

  • pkg:golang/github.com/xuri/excelize/v2 >= 2.7.1, < 2.11.1-0.20260820023833-99903a3240e5

Stated as the source expressed them.