DoS Vulnerability in Excelize Go Library by Qax-os
CVE-2026-107212

7.5HIGH

Key Information:

Vendor

Qax-os

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107212?

The Excelize library, utilized for reading and writing Microsoft Excel files, has a vulnerability in which the Rows.Columns function permits a look-ahead row number beyond the TotalRows limit. This lack of validation can be exploited in specific scenarios where a crafted worksheet includes an oversized row number. Consequently, this allows an attacker to cause a Denial of Service by exhausting CPU resources as the application processes invalid row requests, potentially leading to service degradation. There is no patch currently available to address this issue.

Affected Version(s)

excelize >= 2.1.0, <= 2.11.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.