Integer Overflow Vulnerability in Excelize Library for Spreadsheet Management
CVE-2026-107217
What is CVE-2026-107217?
The Excelize library, used for reading and writing Microsoft Excel spreadsheets, contains a vulnerability in the ColumnNameToNumber function. This issue arises from the handling of column names, which can lead to an integer overflow when processing long column names. Specifically, the function accumulates values without proper overflow detection. When an invalid, long column name such as VGWQHXLSDVIKWV is passed, it wraps to zero and can cause subsequent functions like checkSheetR0 and checkRow to treat the zero index as a negative slice. This flawed behavior may allow an attacker to crash the calling process by manipulating worksheet normalization, highlighting a significant security concern for users of the affected library versions.
Affected Version(s)
excelize >= 2.0.0, <= 2.11.0 <= 2.0.0, 2.11.0
excelize >= 1.1.0, <= 1.4.1 <= 1.1.0, 1.4.1
