Go Language Library Vulnerability in Microsoft Excel Spreadsheet Processing
CVE-2026-107222

6.5MEDIUM

Key Information:

Vendor

Qax-os

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107222?

The Excelize Go library versions 2.7.0 to 2.11.0 contain a vulnerability that affects conditional-format extraction. The library does not properly validate the structure of rules when extracting formats from a worksheet. An attacker can leverage this flaw by supplying a crafted worksheet with incomplete or malformed rules, leading to nil dereferences or attempts to access out-of-range indices. This results in a shocked application state, potentially causing termination of unprotected processes. Currently, there is no patch available to rectify this vulnerability.

Affected Version(s)

excelize >= 2.7.0, <= 2.11.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.