Excelize Go Library Vulnerability Affects Spreadsheet Functionalities
CVE-2026-107220
6.5MEDIUM
What is CVE-2026-107220?
A vulnerability exists in the Excelize Go library affecting versions from 2.7.1 to 2.11.0, where the mergeCellsParser fails to properly handle an empty mergeCell reference. This oversight results in a situation where an empty rectangle is utilized within operations that should contain valid dimensions. Consequently, when an affected worksheet bearing this flaw is read via a non-streaming cell API, it can cause an out-of-bounds access, leading to a panic condition during the first affected cell operation, potentially allowing attackers to disrupt regular functionality.
Affected Version(s)
excelize >= 2.7.1, <= 2.11.0
