Go Language Library for Microsoft Excel Spreadsheets Vulnerability in Excelize
CVE-2026-107213

8.7HIGH

Key Information:

Vendor

Qax-os

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107213?

The Excelize library, utilized for managing Microsoft Excel files via Go, has a vulnerability affecting versions 2.9.0 through 2.11.0. When processing a worksheet containing an extLst element without an associated drawing element, the GetSlicers function can inadvertently dereference a nil pointer, leading to a panic that may crash the application. This flaw could be exploited by crafting a malicious worksheet, resulting in ungraceful termination of services relying on this library. As of now, there are no available fixes, necessitating immediate attention from developers leveraging this library.

Affected Version(s)

excelize >= 2.9.0, <= 2.11.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.