Excelize 是一个用于读取和写入 Microsoft Excel 电子表格的 Go 语言库。在版本 2.1.0 至 2.11.0 之间,当 ZIP64 格式的未压缩大小的高位(high bit)被设置时,该值会从 uint64 类型转换为负的 int64 类型,随后在进行有符号大小限制检查和内存分配时,使用了这个错误的负值。具体而言, 通过 获取 ,并将包装后的负值传递给 函数。当一个精心构造的 ZIP64 条目声明其未压缩大小为 2^63 至 2^64-1 之间的值,且用户打开该工作簿时,该负值会绕过解压大
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107211 | 8.7 HIGH | Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverabl |
| CVE-2026-107213 | 8.7 HIGH | Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but no |
| CVE-2026-107212 | 7.5 HIGH | Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop fo |
| CVE-2026-107214 | 7.5 HIGH | Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks |
| CVE-2026-107216 | 7.5 HIGH | Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly via re-entra |
| CVE-2026-107215 | 7.5 HIGH | Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers |
| CVE-2026-107217 | 7.5 HIGH | Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinate with nil er |
| CVE-2026-107219 | 7.5 HIGH | Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile |
| CVE-2026-107223 | 7.1 HIGH | Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check and expanded pe |
| CVE-2026-107220 | 6.5 MEDIUM | Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref |
| CVE-2026-107221 | 6.5 MEDIUM | Excelize: a row whose earlier cell has a higher column reference than its last cell panics |
| CVE-2026-107222 | 6.5 MEDIUM | Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no l |
| CVE-2026-107225 | 6.5 MEDIUM | Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml |
| CVE-2026-107218 | 5.3 MEDIUM | Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics |
No comments yet