Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or size domain. extractPart trusts the CFB directory entry streamSize for EncryptionInfo and EncryptedPackage allocations before validating the stream. When a crafted OLE compound file declares a negative or extremely large EncryptionInfo or EncryptedPackage stream size, the declared size reaches make with a negative length or forces a multi-gigabyte allocation, allowing an attacker to panic or exhaust process memory. No fixed version is available as of this review.
Published: 2026-10-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Remote Panic / Out-of-Memory Denial of Service
Action: Assess Impact
AI Analysis

Impact

Excelize is a Go library that handles Excel spreadsheets. Between versions 2.3.1 and 2.11.0 a flaw in extractPart allows an attacker to supply a crafted OLE compound file with an attacker‑controlled stream size. The function allocates a byte slice directly from this size before validating the sector chain or bounds. If the size is negative or extremely large, the allocation either panics or consumes multi‑gigabyte amounts of memory, effectively denying service to the calling process.

Affected Systems

The vulnerable product is qax‑os:excelize, with affected releases ranging from 2.3.1 through 2.11.0. No fixed version has been released as of the latest review. Systems that incorporate this library in any application that parses user‑supplied Excel files are at risk.

Risk and Exploitability

The CVSS score is 7.5, indicating high risk. EPSS is currently unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known active exploits. However, an attacker who can supply a malicious spreadsheet to a vulnerable service can trigger a panic or exhaust memory, leading to denial of service. The attack vector is an untrusted file processed by the application, making the threat relevant to any deployment that imports spreadsheets from external sources.

Generated by OpenCVE AI on October 7, 2026 at 19:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the newest release of excelize as soon as it contains the fix
  • If a direct update is not possible, only process spreadsheets from trusted sources and perform strict size checks before calling extractPart
  • Consider running spreadsheet‑processing services in a sandboxed environment or with memory limits to contain potential allocation failures

Generated by OpenCVE AI on October 7, 2026 at 19:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Qax-os
Qax-os excelize
Vendors & Products Qax-os
Qax-os excelize

Wed, 07 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or size domain. extractPart trusts the CFB directory entry streamSize for EncryptionInfo and EncryptedPackage allocations before validating the stream. When a crafted OLE compound file declares a negative or extremely large EncryptionInfo or EncryptedPackage stream size, the declared size reaches make with a negative length or forces a multi-gigabyte allocation, allowing an attacker to panic or exhaust process memory. No fixed version is available as of this review.
Title Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers from CFB directory entries: remote panic / OOM DoS
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T17:48:03.233Z

Reserved: 2026-10-07T14:34:14.815Z

Link: CVE-2026-107215

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T18:17:19.213

Modified: 2026-10-07T18:17:19.213

Link: CVE-2026-107215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:15:17Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value