CVE-2026-107213
Received Received - Intake

Heap Overflow in Excelize via Missing Drawing Element Check

Vulnerability report for CVE-2026-107213, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.9.0 to 2.11.0, GetSlicers checks for ExtLst but dereferences ws.Drawing without checking whether the independently optional drawing element exists. File.GetSlicers reads ws.Drawing.RID after seeing a worksheet extLst element even when the independently optional worksheet drawing element is absent. When a crafted worksheet contains an extLst element without a drawing element and the application calls GetSlicers, the nil ws.Drawing pointer is dereferenced while resolving the drawing relationship, allowing an attacker to panic and terminate an unprotected process. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qax-os excelize >= 2.9.0, <= 2.11.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a nil pointer dereference vulnerability in the Excelize Go library. It occurs when GetSlicers checks for ExtLst but fails to verify if the optional drawing element exists. If a crafted worksheet contains an extLst without a drawing element, the code attempts to access ws.Drawing.RID, causing a panic and process termination.

Detection Guidance

This vulnerability can be detected by checking if your system uses Excelize library versions 2.9.0 to 2.11.0. Inspect Go module files or dependencies for the Excelize package version. No specific commands are provided in the context to exploit or detect this issue actively.

Impact Analysis

An attacker could exploit this to crash applications using vulnerable versions of Excelize (2.9.0 to 2.11.0). This could lead to denial of service, data loss, or unexpected application behavior if not handled properly.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA. It is a nil-pointer dereference issue causing a denial-of-service (DoS) condition in the Excelize library. Compliance impacts would only occur if the DoS disrupts systems processing personal or health data, but the CVE itself does not address data handling or regulatory requirements.

Mitigation Strategies

Immediate mitigation steps include upgrading to a version of Excelize outside the vulnerable range (2.9.0 to 2.11.0) if available. Since no fixed version is available as of the review, consider temporarily disabling the GetSlicers functionality or applying input validation for crafted worksheets. Monitor for updates from the library maintainers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107213. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart