CVE-2026-107214
Received Received - Intake

Excelize Go Library Decryption Input Validation Flaw

Vulnerability report for CVE-2026-107214, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or agileDecrypt before validating the structures used by those routines. When a malformed OLE compound file with a version-valid EncryptionInfo stream is opened or passed to Decrypt, nine malformed-input classes reach unrecovered Go runtime panics instead of the documented error path, allowing an attacker to terminate the calling process. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qax-os excelize >= 2.3.1, <= 2.11.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Excelize Go library for reading and writing Excel files. It occurs when processing malformed but version-valid encrypted Excel files. The Decrypt function fails to validate input structures properly before processing, leading to Go runtime panics instead of returning errors. This can crash the application handling the file.

Detection Guidance

Detecting this vulnerability requires checking if your system uses vulnerable versions of the Excelize library (2.3.1 to 2.11.0). Inspect Go module files or dependency manifests for the excelize package version. No direct network detection commands are provided, but monitoring for application crashes when processing Excel files may indicate exploitation.

Impact Analysis

An attacker could exploit this by providing a specially crafted encrypted Excel file. Opening or processing this file would cause the application to crash, leading to a denial of service. The attack requires no password and can be executed remotely with a small file (100 bytes to 3 KB).

Compliance Impact

This vulnerability primarily causes denial-of-service conditions by crashing applications processing malformed Excel files. For compliance standards like GDPR or HIPAA, which require data integrity and availability, such crashes could disrupt services handling sensitive information, potentially leading to violations if critical data processing is interrupted.

Mitigation Strategies

Immediately upgrade to a patched version if available. Since no fixed version is confirmed in the provided context, avoid processing untrusted Excel files until a patch is released. Implement input validation for Excel files before decryption. Monitor applications using Excelize for crashes during file processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107214. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart