Excelize Go Library Vulnerability in Reading and Writing Spreadsheets
CVE-2026-107221

6.5MEDIUM

Key Information:

Vendor

Qax-os

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107221?

The Excelize library, used for reading and writing Microsoft Excel spreadsheets, is susceptible to an out-of-bounds access vulnerability. This arises when the checkRow function processes spreadsheet cell data from the last cell in XML order, resulting in an insufficient target cell slice length if an improperly configured column order is encountered. An attacker can exploit this by crafting a malicious spreadsheet that inserts cells in a higher column index before a lower column final cell. If this malformed worksheet is accessed via a non-streaming API, it can cause an unrecoverable panic, leading to unexpected termination of the application process. As of now, no patched version is available to mitigate this issue.

Affected Version(s)

excelize >= 2.0.0, <= 2.11.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.