PT-2026-56158 · Excelize · Excelize

CVE-2026-59161

·

Published

2026-07-07

·

Updated

2026-09-10

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Excelize versions prior to 2.11.0
Description The streaming worksheet reader used by the Rows() and GetRows() functions does not enforce the TotalRows limit on the row r attribute. An attacker can provide a small XLSX file containing a row number exceeding 1048576 without a cell coordinate, causing the GetRows() function to append empty rows up to the specified index. This leads to excessive memory and CPU consumption.
Recommendations Update to version 2.11.0.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59161
GHSA-Q5J5-6P94-4GWC

Affected Products

Excelize