Resource Exhaustion Vulnerability in Excelize Library
CVE-2026-107223

7.1HIGH

Key Information:

Vendor

Qax-os

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107223?

The Excelize library, designed for reading and writing Microsoft Excel spreadsheets, contains a flaw in its handling of column ranges. Specifically, from versions 2.1.0 to 2.11.0, the 'flatCols' function fails to validate the minimum and maximum column limits against the defined worksheet boundaries. This oversight allows attackers to exploit oversized column attributes within a crafted worksheet. When a column mutator is called, 'flatCols' performs a deep copy and appends every selected oversized column, leading to significant CPU and memory consumption. If exploited, this vulnerability can result in resource exhaustion or trigger an out-of-memory (OOM) condition. As of the current review, no patched version has been released.

Affected Version(s)

excelize >= 2.1.0, <= 2.11.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.