Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or agileDecrypt before validating the structures used by those routines. When a malformed OLE compound file with a version-valid EncryptionInfo stream is opened or passed to Decrypt, nine malformed-input classes reach unrecovered Go runtime panics instead of the documented error path, allowing an attacker to terminate the calling process. No fixed version is available as of this review.
Published: 2026-10-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Application crash (denial of service)
Action: Assess Impact
AI Analysis

Impact

Excelize, a Go library that handles Microsoft Excel spreadsheets, contains a decryption routine that does not perform sufficient structural and parameter validation before invoking its decryption engines. When a malformed OLE compound file with a seemingly valid EncryptionInfo stream is processed, the library’s standard or agile decryptors slice, index, allocate, or divide using attacker‑controlled values. This leads to a Go runtime panic. The panic propagates back to the calling program and terminates the process, providing the attacker with the ability to crash applications but not to execute arbitrary code or gain further access.

Affected Systems

The issue affects the qax-os:excelize library, specifically versions 2.3.1 through 2.11.0. Projects that import this library and use its Decrypt functions to process user‑supplied or remotely supplied Excel files are at risk. No patched release is available as of this review, so all affected deployments remain vulnerable until an update is published.

Risk and Exploitability

With a CVSS score of 7.5, the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating that no large‑scale exploitation has been observed. The attack vector is inferred to be a local or remote file input; an attacker can supply a corrupted encrypted workbook to trigger the panic, thereby causing a denial of service. Since no arbitrary code execution or privilege escalation is achieved, the primary impact is process termination and downstream availability loss.

Generated by OpenCVE AI on October 7, 2026 at 19:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Avoid decrypting files from untrusted sources; validate file structure before invoking Excelize’s Decrypt routine.
  • Replace or augment Excelize with an alternative Excel handling library or add custom validation of the OLE/CFB structure to ensure it meets expected schemas before calling Decrypt.
  • Monitor the qax-os/excelize GitHub repository and security advisories for a fixed release, and upgrade to the patched version as soon as it becomes available.

Generated by OpenCVE AI on October 7, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Qax-os
Qax-os excelize
Vendors & Products Qax-os
Qax-os excelize
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or agileDecrypt before validating the structures used by those routines. When a malformed OLE compound file with a version-valid EncryptionInfo stream is opened or passed to Decrypt, nine malformed-input classes reach unrecovered Go runtime panics instead of the documented error path, allowing an attacker to terminate the calling process. No fixed version is available as of this review.
Title Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T19:46:20.891Z

Reserved: 2026-10-07T14:34:14.815Z

Link: CVE-2026-107214

cve-icon Vulnrichment

Updated: 2026-10-07T19:46:14.978Z

cve-icon NVD

Status : Received

Published: 2026-10-07T18:17:19.040

Modified: 2026-10-07T20:17:11.320

Link: CVE-2026-107214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:15:17Z

Weaknesses