CVE-2026-107212
Received Received - Intake

Integer Overflow in Excelize Leading to Denial of Service

Vulnerability report for CVE-2026-107212, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Rows.Next and Rows.Columns, but Rows.Columns consumes the row r attribute without the limit check in Rows.Next. When a crafted worksheet places an oversized row number after an ordinary valid row and the application calls GetRows or iterates Rows, the iterator advances through every missing row number instead of rejecting the workbook, allowing an attacker to consume a CPU core for an attacker-controlled duration. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qax-os excelize >= 2.1.0, <= 2.11.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial-of-service vulnerability in the Excelize Go library affecting versions 2.1.0 to 2.11.0. It occurs in the Rows.Columns function which fails to validate row numbers against the maximum allowed rows. While Rows.Next correctly rejects oversized rows, Rows.Columns processes them without checking, causing iterators to process non-existent rows indefinitely and consume CPU resources.

Detection Guidance

Detecting this vulnerability requires checking if your system uses the vulnerable Excelize library versions (2.1.0 to 2.11.0). Inspect Go module dependencies for excelize and verify version numbers. No direct network detection commands are provided in the context.

Impact Analysis

An attacker can craft an Excel file with an extremely high row number that causes applications using Excelize to enter an infinite loop. This leads to prolonged CPU exhaustion, potentially disrupting services that process untrusted Excel files. The impact requires no authentication or user interaction beyond file upload.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling denial-of-service attacks through crafted Excel files. Services processing untrusted files may experience prolonged CPU exhaustion, potentially disrupting operations or delaying access to sensitive data. GDPR requires timely data access and processing, while HIPAA mandates availability of protected health information. The vulnerability does not directly expose data but may hinder compliance by causing system unavailability.

Mitigation Strategies

Immediately upgrade to Excelize v2.11.1 or later which includes the fix. If upgrading is not possible, avoid processing untrusted Excel files until patched. Monitor CPU usage for unexpected spikes during file processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107212. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart