Memory Management Issue in Excelize Library for Microsoft Excel Spreadsheets
CVE-2026-107211
8.7HIGH
What is CVE-2026-107211?
The Excelize library, a Go language tool for handling Microsoft Excel files, has a vulnerability regarding memory management. In versions 2.8.1 through 2.11.0, the library improperly parses pivot-table field indices, leading to potential out-of-bounds access without proper checks. Specifically, the extractPivotTableFields function relies on the dataField field's value as an index when processing pivot-tables. If a specially crafted workbook is utilized—where the pivot-field count is mismatched or the index is out of bounds—it can trigger a slice-bounds panic in Go. This panic can allow an attacker to crash the library's process or the request worker. Currently, a fix is not yet available for this issue.
Affected Version(s)
excelize >= 2.8.1, <= 2.11.0
