Impact
The vulnerability arises when an untrusted Excel workbook contains a pivot‑field count mismatch or an out‑of‑range dataField 'fld' value that is processed by the excelize library. During GetPivotTables the library uses extractPivotTableFields to index the pivot-cache field-name slice without any bounds checks. This causes a Go slice‑bounds panic that propagates out of the library, terminating the process and leading to a denial of service. The primary impact is a crash of the application using the library, which can be leveraged to stop services or degrade availability. The weakness is identified as Improper Validation of Array Index, CWE‑129. Affected systems are applications that depend on the qax‑os excelize library in the 2.8.1 through 2.11.0 range. No official fix is currently available in that release range, and the vulnerability is not listed in the CISA KEV catalog. The attack is limited to situations where a crafted workbook is parsed, so attackers would need either indirect access to supply such a file or compromise the system to import the malicious worksheet.
Affected Systems
Applications that use the qax-os excelize library, versions 2.8.1 through 2.11.0, are affected. This includes any Go code that imports the library to read or write Microsoft Excel spreadsheets and processes user‑supplied workbooks.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, so the current exploitation probability is unknown. Because the flaw requires only the presence of a malicious workbook, there is a realistic potential for remote exploitation in services that load user‑supplied Excel files. There are currently no publicly known exploit packages, but the lack of bounds checking makes the vulnerability highly exploitable if an attacker can supply the workbook.
OpenCVE Enrichment