Excessive Memory Allocation Vulnerability in Excelize Go Library
CVE-2026-107215

7.5HIGH

Key Information:

Vendor

Qax-os

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107215?

The Excelize library, a Go language tool for handling Microsoft Excel files, contains a vulnerability where the extractPart function allocates memory based on an attacker-controlled CFB directory-entry size. Specifically, the function fails to validate the sector chain or the size domain, trusting potentially malicious entries. This flaw could lead to a situation where maliciously crafted OLE compound files specify a negative or exceedingly large size for necessary allocations, resulting in application crashes or process memory exhaustion. As of now, there is no available fix for this issue.

Affected Version(s)

excelize >= 2.3.1, <= 2.11.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.