Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, flatCols expands file-loaded column ranges without validating Min and Max against the worksheet column limit. SetColWidth reaches flatCols, which expands xlsxCol.Min through xlsxCol.Max without enforcing MaxColumns. When a crafted worksheet supplies an oversized col max attribute and the application invokes a column mutator, flatCols performs a deep copy and append for every attacker-selected column number, allowing an attacker to consume excessive CPU and memory or trigger OOM. No fixed version is available as of this review.
Published: 2026-10-07
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via CPU/memory exhaustion leading to application crash
Action: Assess Impact
AI Analysis

Impact

Excelize, a Go library for Excel file handling, contains a flaw where a column definition with an excessively large max attribute is processed without validation. When a column mutator is invoked, the library copies and expands each column entry, causing substantial CPU usage and memory allocation. The outcome is an application hang or out‑of‑memory termination, compromising availability and potentially leading to untrusted data causing resource exhaustion on the host.

Affected Systems

The qax-os:excelize library, versions 2.1.0 through 2.11.0, is affected. Systems using these library releases that load spreadsheets containing oversized column definitions are vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a medium to high severity. There is no public exploit listed and the EPSS score is unavailable, suggesting limited evidence of exploitation in the wild. The flaw is a Memory Allocation weakness (CWE‑789). Attackers can craft a sheet with a large <col max> value and trigger a column mutator to consume CPU and memory resources, potentially causing denial of service. The lack of a vendor patch at this time elevates the risk for environments that process untrusted spreadsheets.

Generated by OpenCVE AI on October 7, 2026 at 20:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Implement resource limits on the process to contain CPU and memory usage
  • Validate and sanitize spreadsheet input before passing it to Excelize, removing or capping excessively large column ranges
  • Filter out or reject spreadsheets with a <col max> value beyond a safe threshold until an official library update is released

Generated by OpenCVE AI on October 7, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fq3v-74gv-27gm Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check and expanded per-column by flatCols(), so any column mutator hangs or OOMs the process
History

Wed, 07 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Qax-os
Qax-os excelize
Vendors & Products Qax-os
Qax-os excelize

Wed, 07 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, flatCols expands file-loaded column ranges without validating Min and Max against the worksheet column limit. SetColWidth reaches flatCols, which expands xlsxCol.Min through xlsxCol.Max without enforcing MaxColumns. When a crafted worksheet supplies an oversized col max attribute and the application invokes a column mutator, flatCols performs a deep copy and append for every attacker-selected column number, allowing an attacker to consume excessive CPU and memory or trigger OOM. No fixed version is available as of this review.
Title Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check and expanded per-column by flatCols(), so any column mutator hangs or OOMs the process
Weaknesses CWE-789
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T22:05:27.449Z

Reserved: 2026-10-07T14:34:14.816Z

Link: CVE-2026-107223

cve-icon Vulnrichment

Updated: 2026-10-07T22:04:07.187Z

cve-icon NVD

Status : Received

Published: 2026-10-07T19:17:34.970

Modified: 2026-10-07T23:17:00.077

Link: CVE-2026-107223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:45:07Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value