Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

excelize — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in excelize, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities for excelize, a widely used Go library for reading and writing Excel files, focusing on common weakness types such as injection, improper input validation, and memory safety issues. The collection aggregates historical security advisories, bug reports, and patch releases spanning from the project’s early development stages through recent updates, capturing the evolution of its security posture over time. Visitors can use this resource to track vendor responses to reported flaws, understand the specific technical contexts of each weakness class within the Go ecosystem, and investigate the vulnerability history of excelize to assess risk exposure for dependent applications. The data is organized to facilitate the correlation between specific CVE identifiers and their underlying causes, allowing developers and security analysts to identify patterns in how input handling, file parsing, or resource management were compromised. By reviewing these aggregated entries, stakeholders can gain insight into the frequency and severity of defects, evaluate the effectiveness of current mitigation strategies, and make informed decisions about library updates or alternative solutions. This summary serves as a neutral reference point for understanding the known security landscape of excelize without promoting any particular vendor narrative or minimizing the impact of identified flaws.

Vendor: qax-os

CVE ID Title CVSS Severity Published
CVE-2026-107225 Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml CWE-20 6.5 Medium 2026-10-07
CVE-2026-107224 Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader CWE-190 6.5 Medium 2026-10-07
CVE-2026-107223 Excelize: Unbounded <col max> attribute is loaded with no MaxColumns check and expanded per-column by flatCols(), so any column mutator hangs or OOMs the process CWE-789 7.1 High 2026-10-07
CVE-2026-107222 Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no length or nil check CWE-129 6.5 Medium 2026-10-07
CVE-2026-107221 Excelize: a row whose earlier cell has a higher column reference than its last cell panics index out of range on almost every worksheet read API CWE-787 6.5 Medium 2026-10-07
CVE-2026-107220 Excelize: Panic in cellInRange on a worksheet with an empty mergeCell ref CWE-125 6.5 Medium 2026-10-07
CVE-2026-107219 Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile CWE-400 7.5 High 2026-10-07
CVE-2026-107218 Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics CWE-129 5.3 Medium 2026-10-07
CVE-2026-107217 Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinate with nil error, causing negative slice index panic on r="0" rows CWE-190 7.5 High 2026-10-07
CVE-2026-107216 Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly via re-entrant CalcCellValue, causing a fatal stack overflow CWE-674 7.5 High 2026-10-07
CVE-2026-107215 Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers from CFB directory entries: remote panic / OOM DoS CWE-789 7.5 High 2026-10-07
CVE-2026-107214 Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks CWE-248 7.5 High 2026-10-07
CVE-2026-107213 Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but no drawing element CWE-476 8.7 High 2026-10-07
CVE-2026-107212 Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop for days CWE-770 7.5 High 2026-10-07
CVE-2026-107211 Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverable panic CWE-129 8.7 High 2026-10-07
CVE-2026-54063 Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS) CWE-770 7.5 High 2026-07-10
CVE-2026-59162 Excelize: Negative shared-string index causes panic in GetCellValue and GetRows CWE-248 - - 2026-07-10
CVE-2026-59161 Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation CWE-400 - - 2026-07-10

All 18 known CVE vulnerabilities affecting excelize with full Chinese analysis, references, and POCs where available.