Excelize 是一个用于读取和写入 Microsoft Excel 电子表格的 Go 语言库。在版本 2.0.0 至 2.11.0 中,checkRow 函数根据 XML 文档中最后一个单元格的大小来初始化目标单元格切片,然后根据每个单元格的显式列引用重新分散所有单元格。GetCellValue 会调用 workSheetReader 和 checkRow,此时目标列表(targetList)对于排序靠前的乱序单元格来说过短。当构造的行中,某一列索引较高的单元格出现在列索引较低的最终单元格之前,并且使用非流式工
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107211 | 8.7 HIGH | Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverabl |
| CVE-2026-107213 | 8.7 HIGH | Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but no |
| CVE-2026-107212 | 7.5 HIGH | Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop fo |
| CVE-2026-107214 | 7.5 HIGH | Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks |
| CVE-2026-107216 | 7.5 HIGH | Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly via re-entra |
| CVE-2026-107215 | 7.5 HIGH | Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers |
| CVE-2026-107217 | 7.5 HIGH | Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinate with nil er |
| CVE-2026-107219 | 7.5 HIGH | Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile |
| CVE-2026-107223 | 7.1 HIGH | Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check and expanded pe |
| CVE-2026-107220 | 6.5 MEDIUM | Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref |
| CVE-2026-107222 | 6.5 MEDIUM | Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no l |
| CVE-2026-107225 | 6.5 MEDIUM | Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml |
| CVE-2026-107224 | 6.5 MEDIUM | Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader |
| CVE-2026-107218 | 5.3 MEDIUM | Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics |
No comments yet