Back to database
Schedule36Medium6.5VulnerabilityCVE-2026-107224No patch link observed

CVE-2026-107224 — Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets.

Published Oct 7, 2026, 07:17 PM UTCIngested 1d agoSource NVD(cve-db)CVE-2026-107224

Description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, a Zip64 uncompressed size with the high bit set is converted from uint64 to a negative int64 before signed size-limit checks and allocation. ReadZipReader obtains UncompressedSize64 through FileInfo.Size and passes the wrapped negative value to readFile. When a crafted Zip64 entry declares an uncompressed size from 2^63 through 2^64-1 and the workbook is opened, the negative size bypasses unzip limits and reaches make as a negative capacity, allowing an attacker to panic during workbook opening. No fixed version is available as of this review.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
6.5

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

Required

User Interaction

S

Unchanged

Scope

C

None

Confidentiality

I

None

Integrity

A

High

Availability

Affected

Vendor
Go
Product
github.com/xuri/excelize/v2

Versions

  • pkg:golang/github.com/xuri/excelize/v2 >= 2.1.0, < 2.11.1-0.20260805032953-db93f8d89de7

Stated as the source expressed them.