PT-2026-56158 · Excelize · Excelize
CVE-2026-59161
·
Published
2026-07-07
·
Updated
2026-09-10
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Excelize versions prior to 2.11.0
Description
The streaming worksheet reader used by the
Rows() and GetRows() functions does not enforce the TotalRows limit on the row r attribute. An attacker can provide a small XLSX file containing a row number exceeding 1048576 without a cell coordinate, causing the GetRows() function to append empty rows up to the specified index. This leads to excessive memory and CPU consumption.Recommendations
Update to version 2.11.0.
Exploit
Fix
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Excelize