Impact
Excelize is a Go library that handles Excel spreadsheets. Between versions 2.3.1 and 2.11.0 a flaw in extractPart allows an attacker to supply a crafted OLE compound file with an attacker‑controlled stream size. The function allocates a byte slice directly from this size before validating the sector chain or bounds. If the size is negative or extremely large, the allocation either panics or consumes multi‑gigabyte amounts of memory, effectively denying service to the calling process.
Affected Systems
The vulnerable product is qax‑os:excelize, with affected releases ranging from 2.3.1 through 2.11.0. No fixed version has been released as of the latest review. Systems that incorporate this library in any application that parses user‑supplied Excel files are at risk.
Risk and Exploitability
The CVSS score is 7.5, indicating high risk. EPSS is currently unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known active exploits. However, an attacker who can supply a malicious spreadsheet to a vulnerable service can trigger a panic or exhaust memory, leading to denial of service. The attack vector is an untrusted file processed by the application, making the threat relevant to any deployment that imports spreadsheets from external sources.
OpenCVE Enrichment