PT-2026-107662 · Excelize · Excelize

CVE-2026-107223

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Excelize versions 2.1.0 through 2.11.0
Description An issue exists where the library fails to validate the Min and Max attributes of column ranges loaded from a file against the worksheet column limit. When a crafted worksheet contains an oversized max attribute in a <col> element, the flatCols() function performs a deep copy and append operation for every column number specified. This occurs when the application invokes column mutator functions, such as SetColWidth(), SetColStyle(), SetColVisible(), or SetColOutlineLevel(). An attacker can exploit this by providing a spreadsheet with a very large max value, leading to excessive CPU and memory consumption, which can result in a permanent hang or an Out-of-Memory (OOM) crash. OOM refers to a state where the system has exhausted its available memory, causing the process to be terminated.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107223
GHSA-FQ3V-74GV-27GM

Affected Products

Excelize