Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Rows.Next and Rows.Columns, but Rows.Columns consumes the row r attribute without the limit check in Rows.Next. When a crafted worksheet places an oversized row number after an ordinary valid row and the application calls GetRows or iterates Rows, the iterator advances through every missing row number instead of rejecting the workbook, allowing an attacker to consume a CPU core for an attacker-controlled duration. No fixed version is available as of this review.
Published: 2026-10-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service via uncontrolled CPU consumption
Action: Apply Patch
AI Analysis

Impact

Excelize is a Go library that read and write Microsoft Excel spreadsheets. Between versions 2.1.0 and 2.11.0, the Rows.Columns method accepted a look‑ahead row number that could exceed the workbook’s total rows without enforcing the limit normally applied by Rows.Next. When a file contains such an oversized row after normal rows, calling GetRows or iterating Rows causes the iterator to traverse every missing row index, which allows an attacker to trigger a long‑running CPU loop, effectively creating a denial‑of‑service scenario. The weakness is a case of unbounded resource consumption (CWE-770).

Affected Systems

The vulnerability affects the Excelize library from the qax‑os vendor. No specific release versions are provided in the CNA data, but the issue exists in the range 2.1.0 to 2.11.0. Any application using these releases at risk of processing untrusted Excel files is potentially impacted.

Risk and Exploitability

The CVSS score is 7.5, indicating a moderate to high severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted workbook supplied to an application that uses Excelize for spreadsheet handling; the attack requires the application to call GetRows or iterate over Rows. An attacker could force the application to consume excessive CPU resources and exhaust a core, leading to service degradation or crash.

Generated by OpenCVE AI on October 7, 2026 at 18:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Excelize library to include the commit that fixes the unbounded row number issue (commit id 01a9ff32).
  • As an interim measure, validate spreadsheet contents to ensure no row indices exceed the workbook’s total rows before calling GetRows or iterating Rows.
  • Monitor the application for unusually high CPU usage and temporarily disable spreadsheet processing when suspicious activity is detected.

Generated by OpenCVE AI on October 7, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Qax-os
Qax-os excelize
Vendors & Products Qax-os
Qax-os excelize

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Rows.Next and Rows.Columns, but Rows.Columns consumes the row r attribute without the limit check in Rows.Next. When a crafted worksheet places an oversized row number after an ordinary valid row and the application calls GetRows or iterates Rows, the iterator advances through every missing row number instead of rejecting the workbook, allowing an attacker to consume a CPU core for an attacker-controlled duration. No fixed version is available as of this review.
Title Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop for days
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T17:57:08.579Z

Reserved: 2026-10-07T14:34:14.815Z

Link: CVE-2026-107212

cve-icon Vulnrichment

Updated: 2026-10-07T17:56:22.508Z

cve-icon NVD

Status : Received

Published: 2026-10-07T18:17:18.670

Modified: 2026-10-07T18:17:18.670

Link: CVE-2026-107212

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:00:12Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling