Excelize 是一个用于读取和写入 Microsoft Excel 电子表格的 Go 语言库。在版本 2.3.1 至 2.11.0 之间,解密分发机制在执行解密操作前,对结构和参数的验证不足。标准解密器和敏捷解密器会使用攻击者控制的值进行切片、索引、分配和划分操作,而在此之前并未充分验证这些结构和参数。解密函数在验证“标准解密”或“敏捷解密”例程所使用的结构之前,就将攻击者控制的 EncryptionInfo 和 EncryptedPackage 数据传递给这些例程。 当打开或传入一个格式错误(malforme
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107211 | 8.7 HIGH | Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverabl |
| CVE-2026-107213 | 8.7 HIGH | Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but no |
| CVE-2026-107212 | 7.5 HIGH | Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop fo |
| CVE-2026-107216 | 7.5 HIGH | Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly via re-entra |
| CVE-2026-107215 | 7.5 HIGH | Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers |
| CVE-2026-107217 | 7.5 HIGH | Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinate with nil er |
| CVE-2026-107219 | 7.5 HIGH | Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile |
| CVE-2026-107223 | 7.1 HIGH | Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check and expanded pe |
| CVE-2026-107220 | 6.5 MEDIUM | Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref |
| CVE-2026-107221 | 6.5 MEDIUM | Excelize: a row whose earlier cell has a higher column reference than its last cell panics |
| CVE-2026-107222 | 6.5 MEDIUM | Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no l |
| CVE-2026-107225 | 6.5 MEDIUM | Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml |
| CVE-2026-107224 | 6.5 MEDIUM | Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader |
| CVE-2026-107218 | 5.3 MEDIUM | Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics |
No comments yet