Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, a Zip64 uncompressed size with the high bit set is converted from uint64 to a negative int64 before signed size-limit checks and allocation. ReadZipReader obtains UncompressedSize64 through FileInfo.Size and passes the wrapped negative value to readFile. When a crafted Zip64 entry declares an uncompressed size from 2^63 through 2^64-1 and the workbook is opened, the negative size bypasses unzip limits and reaches make as a negative capacity, allowing an attacker to panic during workbook opening. No fixed version is available as of this review.
Published: 2026-10-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via crafted Excel file
Action: Monitor for Patch
AI Analysis

Impact

Excelize, a Go library for handling XLSX files, contains a flaw in Zip64 handling between versions 2.1.0 and 2.11.0. The library incorrectly converts a Zip64 uncompressed size that has its high bit set from an unsigned 64‑bit integer to a signed 64‑bit integer. This conversion bypasses size‑limit checks and allows a negative capacity value to be passed to memory allocation. When a specially crafted workbook declares an uncompressed size in the range 2^63 to 2^64 – 1, opening the file causes the library to panic, leading to a denial of service.

Affected Systems

Vendors affected are qax‑os:excelize, specifically all releases from 2.1.0 through 2.11.0. No patched release is available at the time of this review, so anyone using these versions remains vulnerable.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no broad exploitation community coverage yet. Based on the description, the likely attack vector involves an attacker delivering a malicious Excel file that contains a Zip64 entry with a large uncompressed size, causing the library to panic when the file is opened. No code execution is possible, but the crash can be used to disrupt services that rely on Excelize.

Generated by OpenCVE AI on October 7, 2026 at 20:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the fixed patch from the repository when a new release becomes available or manually merge the commit that resolves the Zip64 size conversion issue
  • Add pre‑validation to reject XLSX files whose Zip64 uncompressed size is greater than or equal to 2^63 before calling any Excelize functions
  • Process unknown Excel files in a sandboxed environment to contain potential crashes produced by the library

Generated by OpenCVE AI on October 7, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fw94-4wwp-w8pw Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader
History

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Qax-os
Qax-os excelize
Vendors & Products Qax-os
Qax-os excelize

Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, a Zip64 uncompressed size with the high bit set is converted from uint64 to a negative int64 before signed size-limit checks and allocation. ReadZipReader obtains UncompressedSize64 through FileInfo.Size and passes the wrapped negative value to readFile. When a crafted Zip64 entry declares an uncompressed size from 2^63 through 2^64-1 and the workbook is opened, the negative size bypasses unzip limits and reaches make as a negative capacity, allowing an attacker to panic during workbook opening. No fixed version is available as of this review.
Title Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader
Weaknesses CWE-190
CWE-681
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T19:30:13.733Z

Reserved: 2026-10-07T14:34:14.816Z

Link: CVE-2026-107224

cve-icon Vulnrichment

Updated: 2026-10-07T19:30:07.190Z

cve-icon NVD

Status : Received

Published: 2026-10-07T19:17:35.140

Modified: 2026-10-07T20:17:11.713

Link: CVE-2026-107224

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:45:07Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-681

    Incorrect Conversion between Numeric Types