Zip64 Uncompressed Size Vulnerability in Excelize Library
CVE-2026-107224
6.5MEDIUM
What is CVE-2026-107224?
The Excelize library, a Go language tool for managing Microsoft Excel files, contains a vulnerability due to improper handling of Zip64 uncompressed sizes. When dealing with specific large file sizes within the range of 2^63 to 2^64-1, the library incorrectly converts these values from uint64 to a negative int64. This flaw occurs in versions 2.1.0 through 2.11.0, allowing a crafted Zip64 entry to bypass size limits and invoke panic during workbook opening, potentially leading to unexpected behavior or application crashes. Currently, there is no patched version available to address this issue.
Affected Version(s)
excelize >= 2.1.0, <= 2.11.0
