Excelize 是一个用于读取和写入 Microsoft Excel 电子表格的 Go 语言库。在版本 2.7.0 到 2.11.0 之间,条件格式提取过程中存在以下问题:某些索引操作依赖于子切片,或访问可选的 colorScale 子元素,但未对格式不正确的规则结构进行验证。 具体而言, 函数会调用 ,并访问 、 以及 等字段,但缺少完整的结构检查。当构造的 Excel 工作表中包含缺少预期子元素的 cellIs、dataBar 或 colorScale 规则时,如果应用程序调用 ,则缺失的公式、颜色、值对象或
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107211 | 8.7 HIGH | Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverabl |
| CVE-2026-107213 | 8.7 HIGH | Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but no |
| CVE-2026-107212 | 7.5 HIGH | Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop fo |
| CVE-2026-107214 | 7.5 HIGH | Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks |
| CVE-2026-107216 | 7.5 HIGH | Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly via re-entra |
| CVE-2026-107215 | 7.5 HIGH | Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers |
| CVE-2026-107217 | 7.5 HIGH | Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinate with nil er |
| CVE-2026-107219 | 7.5 HIGH | Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile |
| CVE-2026-107223 | 7.1 HIGH | Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check and expanded pe |
| CVE-2026-107220 | 6.5 MEDIUM | Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref |
| CVE-2026-107221 | 6.5 MEDIUM | Excelize: a row whose earlier cell has a higher column reference than its last cell panics |
| CVE-2026-107225 | 6.5 MEDIUM | Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml |
| CVE-2026-107224 | 6.5 MEDIUM | Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader |
| CVE-2026-107218 | 5.3 MEDIUM | Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics |
No comments yet