Resource Exhaustion Vulnerability in Excelize Library
CVE-2026-107223
What is CVE-2026-107223?
The Excelize library, designed for reading and writing Microsoft Excel spreadsheets, contains a flaw in its handling of column ranges. Specifically, from versions 2.1.0 to 2.11.0, the 'flatCols' function fails to validate the minimum and maximum column limits against the defined worksheet boundaries. This oversight allows attackers to exploit oversized column attributes within a crafted worksheet. When a column mutator is called, 'flatCols' performs a deep copy and appends every selected oversized column, leading to significant CPU and memory consumption. If exploited, this vulnerability can result in resource exhaustion or trigger an out-of-memory (OOM) condition. As of the current review, no patched version has been released.
Affected Version(s)
excelize >= 2.1.0, <= 2.11.0
