Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-flight and iteration controls. ANCHORARRAY calls CalcCellValue instead of cellResolver, so each recursive hop receives a new calcContext and loses cycle state. When mutually referencing dynamic-array formulas are evaluated directly or through formula-evaluating APIs, each recursion hop resets the cycle budget and prevents completion-based caches from breaking the cycle, allowing an attacker to cause a fatal Go stack overflow and abort the process. No fixed version is available as of this review.
Published: 2026-10-07
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Monitor
AI Analysis

Impact

Excelize contains a flaw that causes the ANCHORARRAY function to call the CalcCellValue routine recursively without reusing the existing calculation context. Each recursive hop creates a new context, discarding the cycle budget and any completion-based caches. When users load workbooks that contain mutually referencing dynamic array formulas, an attacker can trigger an unbounded recursion that exhausts the Go runtime stack and forces the process to abort. The result is a denial of service: the application stops responding or crashes during formula evaluation.

Affected Systems

The vulnerability is present in the qax-os:excelize library from version 2.8.1 through 2.11.0. Applications that incorporate one of these library versions and process untrusted Excel files are impacted.

Risk and Exploitability

The CVSS score of 7.5 categorizes the risk as high. While an EPSS score is not reported, the lack of a mitigation and the nature of the attack suggest that exploitation is plausible, especially in environments that load arbitrary spreadsheets without input validation. The vulnerability is not listed in the CISA KEV catalog, but the high severity and the potential for an unbounded stack consumption make it a priority for patching or other controls. The attack vector is inferred to be through a client or server component that imports a malicious Excel file and triggers the formula evaluation, leading to a fatal stack overflow.

Generated by OpenCVE AI on October 7, 2026 at 19:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest released version of excelize once a fix is available.
  • Validate or sanitize Excel files before they are processed, removing or restricting dynamic array formulas that could reference each other.
  • Implement application‑level stack or resource limits to constrain the recursion depth and prevent a stack overflow from crashing the process.

Generated by OpenCVE AI on October 7, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Qax-os
Qax-os excelize
Vendors & Products Qax-os
Qax-os excelize

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-flight and iteration controls. ANCHORARRAY calls CalcCellValue instead of cellResolver, so each recursive hop receives a new calcContext and loses cycle state. When mutually referencing dynamic-array formulas are evaluated directly or through formula-evaluating APIs, each recursion hop resets the cycle budget and prevents completion-based caches from breaking the cycle, allowing an attacker to cause a fatal Go stack overflow and abort the process. No fixed version is available as of this review.
Title Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly via re-entrant CalcCellValue, causing a fatal stack overflow
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T18:51:04.748Z

Reserved: 2026-10-07T14:34:14.815Z

Link: CVE-2026-107216

cve-icon Vulnrichment

Updated: 2026-10-07T18:50:59.479Z

cve-icon NVD

Status : Received

Published: 2026-10-07T18:17:19.400

Modified: 2026-10-07T19:17:33.837

Link: CVE-2026-107216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:15:17Z

Weaknesses