Impact
Excelize is a Go library for manipulating Excel files. Between releases 2.7.0 and 2.11.0, the GetConditionalFormats function can index child elements of a conditional‑formatting rule without ensuring the expected slices or pointers exist. A craft spreadsheet that omits required children leads to an out‑of‑range index or nil dereference when the function accesses ColorScale.Cfvo, DataBar.Cfvo, or DataBar.Color. The missing data causes a panic that unconditionally terminates the process. The vulnerability therefore provides a denial‑of‑service vector by allowing an attacker to crash an unprotected application that calls the function.
Affected Systems
Vulnerable versions are Excelize 2.7.0 through 2.11.0. The library is maintained by qax‑os and used in any Go application that processes Excel files by calling GetConditionalFormats. No fixed release exists at the time of this review.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers need only supply a malicious workbook that triggers the error; the attack vector is a crafted input file. Exploitation does not require elevated privileges or code execution, but it can terminate the target service. Overall risk is moderate but mitigable by disabling the function or applying safeguards.
OpenCVE Enrichment
Github GHSA