DoS Vulnerability in Excelize Go Library by Qax-os
CVE-2026-107212
7.5HIGH
What is CVE-2026-107212?
The Excelize library, utilized for reading and writing Microsoft Excel files, has a vulnerability in which the Rows.Columns function permits a look-ahead row number beyond the TotalRows limit. This lack of validation can be exploited in specific scenarios where a crafted worksheet includes an oversized row number. Consequently, this allows an attacker to cause a Denial of Service by exhausting CPU resources as the application processes invalid row requests, potentially leading to service degradation. There is no patch currently available to address this issue.
Affected Version(s)
excelize >= 2.1.0, <= 2.11.0
