Impact
Excelize, a Go library for Excel file handling, contains a flaw where a column definition with an excessively large max attribute is processed without validation. When a column mutator is invoked, the library copies and expands each column entry, causing substantial CPU usage and memory allocation. The outcome is an application hang or out‑of‑memory termination, compromising availability and potentially leading to untrusted data causing resource exhaustion on the host.
Affected Systems
The qax-os:excelize library, versions 2.1.0 through 2.11.0, is affected. Systems using these library releases that load spreadsheets containing oversized column definitions are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium to high severity. There is no public exploit listed and the EPSS score is unavailable, suggesting limited evidence of exploitation in the wild. The flaw is a Memory Allocation weakness (CWE‑789). Attackers can craft a sheet with a large <col max> value and trigger a column mutator to consume CPU and memory resources, potentially causing denial of service. The lack of a vendor patch at this time elevates the risk for environments that process untrusted spreadsheets.
OpenCVE Enrichment
Github GHSA