Excelize Go Library Vulnerability in Reading and Writing Spreadsheets
CVE-2026-107221
What is CVE-2026-107221?
The Excelize library, used for reading and writing Microsoft Excel spreadsheets, is susceptible to an out-of-bounds access vulnerability. This arises when the checkRow function processes spreadsheet cell data from the last cell in XML order, resulting in an insufficient target cell slice length if an improperly configured column order is encountered. An attacker can exploit this by crafting a malicious spreadsheet that inserts cells in a higher column index before a lower column final cell. If this malformed worksheet is accessed via a non-streaming API, it can cause an unrecoverable panic, leading to unexpected termination of the application process. As of now, no patched version is available to mitigate this issue.
Affected Version(s)
excelize >= 2.0.0, <= 2.11.0
