Go Language Library Vulnerability in Excelize Affects Spreadsheet Management
CVE-2026-107216
7.5HIGH
What is CVE-2026-107216?
Excelize is a library written in Go for reading and writing Microsoft Excel spreadsheets. A vulnerability has been discovered that affects versions from 2.8.1 to 2.11.0. The issue arises from the ANCHORARRAY function, which makes recursive calls to the CalcCellValue function, leading to the loss of iteration controls and the cycling state. When formulas which reference themselves are evaluated through various APIs, each recursive call resets the calculation context, resulting in a stack overflow that could cause the program to abort. Currently, no fixed version has been released to address this vulnerability.
Affected Version(s)
excelize >= 2.8.1, <= 2.11.0
