Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.9.0 to 2.11.0, GetSlicers checks for ExtLst but dereferences ws.Drawing without checking whether the independently optional drawing element exists. File.GetSlicers reads ws.Drawing.RID after seeing a worksheet extLst element even when the independently optional worksheet drawing element is absent. When a crafted worksheet contains an extLst element without a drawing element and the application calls GetSlicers, the nil ws.Drawing pointer is dereferenced while resolving the drawing relationship, allowing an attacker to panic and terminate an unprotected process. No fixed version is available as of this review.
Published: 2026-10-07
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service via application crash
Action: Assess Impact
AI Analysis

Impact

Excelize, a Go library for handling Excel spreadsheets, contains a nil‑pointer dereference in the GetSlicers method. When a worksheet contains an extLst element but no drawing element, the library dereferences a nil drawing pointer, causing a panic that terminates the calling process. This is a classic null pointer dereference identified as CWE‑476, resulting in denial of service for any application that imports or processes such files.

Affected Systems

The vulnerability affects the qax-os:excelize library, specifically versions 2.9.0 through 2.11.0. No fixed version is available at the time of this review, and the issue is not listed in the CISA KEV catalog.

Risk and Exploitability

With a CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not present in the KEV list, suggesting the risk is primarily due to the lack of an immediate fix. Attackers can exploit this by crafting a malicious worksheet file that triggers GetSlicers, leading to a crash in unprotected usage contexts. The likely attack vector is local or injected input into an application that uses Excelize without additional controls.

Generated by OpenCVE AI on October 7, 2026 at 18:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a future fixed release of Excelize as soon as it becomes available.
  • In the interim, avoid invoking GetSlicers on untrusted or unvalidated worksheets, or replace that call with a safer alternative that performs necessary nil checks.
  • Wrap GetSlicers calls in a recover block to catch the panic and prevent the entire application from terminating.

Generated by OpenCVE AI on October 7, 2026 at 18:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Qax-os
Qax-os excelize
Vendors & Products Qax-os
Qax-os excelize

Wed, 07 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.9.0 to 2.11.0, GetSlicers checks for ExtLst but dereferences ws.Drawing without checking whether the independently optional drawing element exists. File.GetSlicers reads ws.Drawing.RID after seeing a worksheet extLst element even when the independently optional worksheet drawing element is absent. When a crafted worksheet contains an extLst element without a drawing element and the application calls GetSlicers, the nil ws.Drawing pointer is dereferenced while resolving the drawing relationship, allowing an attacker to panic and terminate an unprotected process. No fixed version is available as of this review.
Title Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but no drawing element
Weaknesses CWE-476
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T17:40:29.865Z

Reserved: 2026-10-07T14:34:14.815Z

Link: CVE-2026-107213

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T18:17:18.860

Modified: 2026-10-07T18:17:18.860

Link: CVE-2026-107213

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:15:17Z

Weaknesses