CVE-2026-107223 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.
Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, flatCols expands file-loaded column ranges without validating Min and Max against the worksheet column limit. SetColWidth reaches flatCols, which expands xlsxCol.Min through xlsxCol.Max without enforcing MaxColumns. When a crafted worksheet supplies an oversized col max attribute and the application invokes a column mutator, flatCols performs a deep copy and append for every attacker-selected column number, allowing an attacker to consume excessive CPU and memory or trigger OOM. No fixed version is available as of this review.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
None
Privileges Required
UI
Passive
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
High
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Affected
- Vendor
- Go
- Product
- github.com/xuri/excelize/v2
Versions
- pkg:golang/github.com/xuri/excelize/v2 >= 2.1.0, < 2.11.1-0.20260807015645-a54c578af309
Stated as the source expressed them.
References
- advisory[email protected]https://github.com/qax-os/excelize/commit/a54c578af309fa81f448143ed2b7a91192cc58a7
- advisory[email protected]https://github.com/qax-os/excelize/pull/2370
- advisory[email protected]https://github.com/qax-os/excelize/security/advisories/GHSA-fq3v-74gv-27gm
- advisoryOSV GHSA-fq3v-74gv-27gmhttps://osv.dev/vulnerability/GHSA-fq3v-74gv-27gm
- vendorOSV packagehttps://github.com/qax-os/excelize
Related threats
same CWE or vendorCVE-2026-107390 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107390 · 3h ago
CVE-2026-107389 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107389 · 3h ago
CVE-2026-107388 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107388 · 4h ago
CVE-2026-107387 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107387 · 4h ago
CVE-2026-107386 — amqp091-go is a Go AMQP 0.9.1 client.
CVE-2026-107386 · 4h ago
Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor
OSV · 5h ago