PT-2026-107661 · Excelize · Excelize
CVE-2026-107222
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Excelize versions 2.7.0 through 2.11.0
Description
An issue exists when extracting conditional formats from a crafted worksheet. The
GetConditionalFormats() function fails to properly validate the structure of certain rules, specifically cellIs, dataBar, and colorScale. This occurs because the library indexes child slices or dereferences optional children without verifying their existence or length. Specifically, the extractCondFmtCellIs() function may index an empty Formula slice, and the colorScale and dataBar extractors may encounter nil pointers or out-of-range indexes when accessing Cfvo and Color variables. An attacker can exploit this by providing a malformed spreadsheet, causing the application to panic and terminate the process.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
NULL Pointer Dereference
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Excelize