Integer Overflow Vulnerability in Excelize Library for Spreadsheet Management
CVE-2026-107217

7.5HIGH

Key Information:

Vendor

Qax-os

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107217?

The Excelize library, used for reading and writing Microsoft Excel spreadsheets, contains a vulnerability in the ColumnNameToNumber function. This issue arises from the handling of column names, which can lead to an integer overflow when processing long column names. Specifically, the function accumulates values without proper overflow detection. When an invalid, long column name such as VGWQHXLSDVIKWV is passed, it wraps to zero and can cause subsequent functions like checkSheetR0 and checkRow to treat the zero index as a negative slice. This flawed behavior may allow an attacker to crash the calling process by manipulating worksheet normalization, highlighting a significant security concern for users of the affected library versions.

Affected Version(s)

excelize >= 2.0.0, <= 2.11.0 <= 2.0.0, 2.11.0

excelize >= 1.1.0, <= 1.4.1 <= 1.1.0, 1.4.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.