Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks. extractPivotTableFields uses getPivotCacheFieldsName output while processing GetPivotTables and trusts the dataField fld attribute as an index. When a crafted workbook supplies a pivot-field count mismatch or an out-of-range dataField fld value before GetPivotTables is called, the unchecked index causes a Go slice-bounds panic that escapes the library, allowing an attacker to crash the process or request worker. No fixed version is available as of this review.
Published: 2026-10-07
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Implement Controls
AI Analysis

Impact

The vulnerability arises when an untrusted Excel workbook contains a pivot‑field count mismatch or an out‑of‑range dataField 'fld' value that is processed by the excelize library. During GetPivotTables the library uses extractPivotTableFields to index the pivot-cache field-name slice without any bounds checks. This causes a Go slice‑bounds panic that propagates out of the library, terminating the process and leading to a denial of service. The primary impact is a crash of the application using the library, which can be leveraged to stop services or degrade availability. The weakness is identified as Improper Validation of Array Index, CWE‑129. Affected systems are applications that depend on the qax‑os excelize library in the 2.8.1 through 2.11.0 range. No official fix is currently available in that release range, and the vulnerability is not listed in the CISA KEV catalog. The attack is limited to situations where a crafted workbook is parsed, so attackers would need either indirect access to supply such a file or compromise the system to import the malicious worksheet.

Affected Systems

Applications that use the qax-os excelize library, versions 2.8.1 through 2.11.0, are affected. This includes any Go code that imports the library to read or write Microsoft Excel spreadsheets and processes user‑supplied workbooks.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is not available, so the current exploitation probability is unknown. Because the flaw requires only the presence of a malicious workbook, there is a realistic potential for remote exploitation in services that load user‑supplied Excel files. There are currently no publicly known exploit packages, but the lack of bounds checking makes the vulnerability highly exploitable if an attacker can supply the workbook.

Generated by OpenCVE AI on October 7, 2026 at 18:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Monitor qax-os for a patch and upgrade when a fixed version is released.
  • Implement custom bounds checking around pivot-cache field accesses in your code if an immediate library upgrade is not possible.
  • Restrict or validate any untrusted Excel workbooks before they are processed until a patch is applied.
  • Use application‑level panic recovery to catch the goroutine panic and prevent process termination.

Generated by OpenCVE AI on October 7, 2026 at 18:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Qax-os
Qax-os excelize
Vendors & Products Qax-os
Qax-os excelize
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks. extractPivotTableFields uses getPivotCacheFieldsName output while processing GetPivotTables and trusts the dataField fld attribute as an index. When a crafted workbook supplies a pivot-field count mismatch or an out-of-range dataField fld value before GetPivotTables is called, the unchecked index causes a Go slice-bounds panic that escapes the library, allowing an attacker to crash the process or request worker. No fixed version is available as of this review.
Title Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverable panic
Weaknesses CWE-129
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T19:03:18.640Z

Reserved: 2026-10-07T14:34:14.815Z

Link: CVE-2026-107211

cve-icon Vulnrichment

Updated: 2026-10-07T19:03:09.508Z

cve-icon NVD

Status : Received

Published: 2026-10-07T18:17:18.490

Modified: 2026-10-07T19:17:33.660

Link: CVE-2026-107211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:15:17Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index