Impact
Excelize contains a flaw that causes the ANCHORARRAY function to call the CalcCellValue routine recursively without reusing the existing calculation context. Each recursive hop creates a new context, discarding the cycle budget and any completion-based caches. When users load workbooks that contain mutually referencing dynamic array formulas, an attacker can trigger an unbounded recursion that exhausts the Go runtime stack and forces the process to abort. The result is a denial of service: the application stops responding or crashes during formula evaluation.
Affected Systems
The vulnerability is present in the qax-os:excelize library from version 2.8.1 through 2.11.0. Applications that incorporate one of these library versions and process untrusted Excel files are impacted.
Risk and Exploitability
The CVSS score of 7.5 categorizes the risk as high. While an EPSS score is not reported, the lack of a mitigation and the nature of the attack suggest that exploitation is plausible, especially in environments that load arbitrary spreadsheets without input validation. The vulnerability is not listed in the CISA KEV catalog, but the high severity and the potential for an unbounded stack consumption make it a priority for patching or other controls. The attack vector is inferred to be through a client or server component that imports a malicious Excel file and triggers the formula evaluation, leading to a fatal stack overflow.
OpenCVE Enrichment