PT-2026-107661 · Excelize · Excelize

CVE-2026-107222

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Excelize versions 2.7.0 through 2.11.0
Description An issue exists when extracting conditional formats from a crafted worksheet. The GetConditionalFormats() function fails to properly validate the structure of certain rules, specifically cellIs, dataBar, and colorScale. This occurs because the library indexes child slices or dereferences optional children without verifying their existence or length. Specifically, the extractCondFmtCellIs() function may index an empty Formula slice, and the colorScale and dataBar extractors may encounter nil pointers or out-of-range indexes when accessing Cfvo and Color variables. An attacker can exploit this by providing a malformed spreadsheet, causing the application to panic and terminate the process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

NULL Pointer Dereference

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107222
GHSA-RXCJ-4PJ5-74GR

Affected Products

Excelize