Excessive Memory Allocation Vulnerability in Excelize Go Library
CVE-2026-107215
7.5HIGH
What is CVE-2026-107215?
The Excelize library, a Go language tool for handling Microsoft Excel files, contains a vulnerability where the extractPart function allocates memory based on an attacker-controlled CFB directory-entry size. Specifically, the function fails to validate the sector chain or the size domain, trusting potentially malicious entries. This flaw could lead to a situation where maliciously crafted OLE compound files specify a negative or exceedingly large size for necessary allocations, resulting in application crashes or process memory exhaustion. As of now, there is no available fix for this issue.
Affected Version(s)
excelize >= 2.3.1, <= 2.11.0
