Excelize 是一个用于读写 Microsoft Excel 电子表格的 Go 语言库。在版本 2.1.0 至 2.11.0 中, 方法允许传入一个超出 (总行数)的“前瞻”行号,而未应用由 所执行的边界限制。 依赖于 和 ,但 在没有 中进行限制检查的情况下,会直接消耗行属性 。当构造的电子表格在一个普通有效行之后放置一个过大的行号,并且应用程序调用 或迭代 时,迭代器会跳过所有缺失的行号,而不是拒绝该工作簿。这允许攻击者在可控的时间内消耗一个 CPU 核心资源。截至本次审查时,尚无修复版本可用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107211 | 8.7 HIGH | Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverabl |
| CVE-2026-107213 | 8.7 HIGH | Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but no |
| CVE-2026-107214 | 7.5 HIGH | Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks |
| CVE-2026-107216 | 7.5 HIGH | Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly via re-entra |
| CVE-2026-107215 | 7.5 HIGH | Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers |
| CVE-2026-107217 | 7.5 HIGH | Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinate with nil er |
| CVE-2026-107219 | 7.5 HIGH | Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile |
| CVE-2026-107223 | 7.1 HIGH | Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check and expanded pe |
| CVE-2026-107220 | 6.5 MEDIUM | Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref |
| CVE-2026-107221 | 6.5 MEDIUM | Excelize: a row whose earlier cell has a higher column reference than its last cell panics |
| CVE-2026-107222 | 6.5 MEDIUM | Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no l |
| CVE-2026-107225 | 6.5 MEDIUM | Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml |
| CVE-2026-107224 | 6.5 MEDIUM | Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader |
| CVE-2026-107218 | 5.3 MEDIUM | Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics |
No comments yet