Go Language Library Vulnerability in Excelize Affects Spreadsheet Management
CVE-2026-107216

7.5HIGH

Key Information:

Vendor

Qax-os

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107216?

Excelize is a library written in Go for reading and writing Microsoft Excel spreadsheets. A vulnerability has been discovered that affects versions from 2.8.1 to 2.11.0. The issue arises from the ANCHORARRAY function, which makes recursive calls to the CalcCellValue function, leading to the loss of iteration controls and the cycling state. When formulas which reference themselves are evaluated through various APIs, each recursive call resets the calculation context, resulting in a stack overflow that could cause the program to abort. Currently, no fixed version has been released to address this vulnerability.

Affected Version(s)

excelize >= 2.8.1, <= 2.11.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.