Excelize Go Library Vulnerability Affects Spreadsheet Functionalities
CVE-2026-107220

6.5MEDIUM

Key Information:

Vendor

Qax-os

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107220?

A vulnerability exists in the Excelize Go library affecting versions from 2.7.1 to 2.11.0, where the mergeCellsParser fails to properly handle an empty mergeCell reference. This oversight results in a situation where an empty rectangle is utilized within operations that should contain valid dimensions. Consequently, when an affected worksheet bearing this flaw is read via a non-streaming cell API, it can cause an out-of-bounds access, leading to a panic condition during the first affected cell operation, potentially allowing attackers to disrupt regular functionality.

Affected Version(s)

excelize >= 2.7.1, <= 2.11.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.