Impact
Excelize is a Go library that read and write Microsoft Excel spreadsheets. Between versions 2.1.0 and 2.11.0, the Rows.Columns method accepted a look‑ahead row number that could exceed the workbook’s total rows without enforcing the limit normally applied by Rows.Next. When a file contains such an oversized row after normal rows, calling GetRows or iterating Rows causes the iterator to traverse every missing row index, which allows an attacker to trigger a long‑running CPU loop, effectively creating a denial‑of‑service scenario. The weakness is a case of unbounded resource consumption (CWE-770).
Affected Systems
The vulnerability affects the Excelize library from the qax‑os vendor. No specific release versions are provided in the CNA data, but the issue exists in the range 2.1.0 to 2.11.0. Any application using these releases at risk of processing untrusted Excel files is potentially impacted.
Risk and Exploitability
The CVSS score is 7.5, indicating a moderate to high severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted workbook supplied to an application that uses Excelize for spreadsheet handling; the attack requires the application to call GetRows or iterate over Rows. An attacker could force the application to consume excessive CPU resources and exhaust a core, leading to service degradation or crash.
OpenCVE Enrichment