Impact
Excelize, a Go library for handling XLSX files, contains a flaw in Zip64 handling between versions 2.1.0 and 2.11.0. The library incorrectly converts a Zip64 uncompressed size that has its high bit set from an unsigned 64‑bit integer to a signed 64‑bit integer. This conversion bypasses size‑limit checks and allows a negative capacity value to be passed to memory allocation. When a specially crafted workbook declares an uncompressed size in the range 2^63 to 2^64 – 1, opening the file causes the library to panic, leading to a denial of service.
Affected Systems
Vendors affected are qax‑os:excelize, specifically all releases from 2.1.0 through 2.11.0. No patched release is available at the time of this review, so anyone using these versions remains vulnerable.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no broad exploitation community coverage yet. Based on the description, the likely attack vector involves an attacker delivering a malicious Excel file that contains a Zip64 entry with a large uncompressed size, causing the library to panic when the file is opened. No code execution is possible, but the crash can be used to disrupt services that rely on Excelize.
OpenCVE Enrichment
Github GHSA