Excelize 是一个用于读取和写入 Microsoft Excel 电子表格的 Go 语言库。在版本 2.8.1 至 2.11.0 中,ANCHORARRAY 会递归调用导出的 CalcCellValue 函数,在每次递归循环中创建新的计算上下文,从而绕过了正在进行的控制(in-flight)和迭代控制(iteration controls)。由于 ANCHORARRAY 调用的是 CalcCellValue 而非 cellResolver,每次递归调用都会获得一个新的 calcContext,导致循环状态(c
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107211 | 8.7 HIGH | Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverabl |
| CVE-2026-107213 | 8.7 HIGH | Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but no |
| CVE-2026-107212 | 7.5 HIGH | Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop fo |
| CVE-2026-107214 | 7.5 HIGH | Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks |
| CVE-2026-107215 | 7.5 HIGH | Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers |
| CVE-2026-107217 | 7.5 HIGH | Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinate with nil er |
| CVE-2026-107219 | 7.5 HIGH | Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile |
| CVE-2026-107223 | 7.1 HIGH | Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check and expanded pe |
| CVE-2026-107220 | 6.5 MEDIUM | Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref |
| CVE-2026-107221 | 6.5 MEDIUM | Excelize: a row whose earlier cell has a higher column reference than its last cell panics |
| CVE-2026-107222 | 6.5 MEDIUM | Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no l |
| CVE-2026-107225 | 6.5 MEDIUM | Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml |
| CVE-2026-107224 | 6.5 MEDIUM | Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader |
| CVE-2026-107218 | 5.3 MEDIUM | Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics |
No comments yet