PT-2026-107662 · Excelize · Excelize
CVE-2026-107223
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Excelize versions 2.1.0 through 2.11.0
Description
An issue exists where the library fails to validate the
Min and Max attributes of column ranges loaded from a file against the worksheet column limit. When a crafted worksheet contains an oversized max attribute in a <col> element, the flatCols() function performs a deep copy and append operation for every column number specified. This occurs when the application invokes column mutator functions, such as SetColWidth(), SetColStyle(), SetColVisible(), or SetColOutlineLevel(). An attacker can exploit this by providing a spreadsheet with a very large max value, leading to excessive CPU and memory consumption, which can result in a permanent hang or an Out-of-Memory (OOM) crash. OOM refers to a state where the system has exhausted its available memory, causing the process to be terminated.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Excelize