Memory Management Issue in Excelize Library for Microsoft Excel Spreadsheets
CVE-2026-107211

8.7HIGH

Key Information:

Vendor

Qax-os

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107211?

The Excelize library, a Go language tool for handling Microsoft Excel files, has a vulnerability regarding memory management. In versions 2.8.1 through 2.11.0, the library improperly parses pivot-table field indices, leading to potential out-of-bounds access without proper checks. Specifically, the extractPivotTableFields function relies on the dataField field's value as an index when processing pivot-tables. If a specially crafted workbook is utilized—where the pivot-field count is mismatched or the index is out of bounds—it can trigger a slice-bounds panic in Go. This panic can allow an attacker to crash the library's process or the request worker. Currently, a fix is not yet available for this issue.

Affected Version(s)

excelize >= 2.8.1, <= 2.11.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.