CVE-2026-107216
Received Received - Intake

Stack Overflow in Excelize Go Library

Vulnerability report for CVE-2026-107216, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, ANCHORARRAY recursively calls the exported CalcCellValue function, creating a fresh calculation context at each cycle and bypassing in-flight and iteration controls. ANCHORARRAY calls CalcCellValue instead of cellResolver, so each recursive hop receives a new calcContext and loses cycle state. When mutually referencing dynamic-array formulas are evaluated directly or through formula-evaluating APIs, each recursion hop resets the cycle budget and prevents completion-based caches from breaking the cycle, allowing an attacker to cause a fatal Go stack overflow and abort the process. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qax-os excelize >= 2.8.1, <= 2.11.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Excelize Go library for Excel files. It involves the ANCHORARRAY function which, between versions 2.8.1 and 2.11.0, recursively calls CalcCellValue without proper cycle detection. Each call creates a new calculation context, bypassing controls for circular references. This leads to infinite recursion when formulas reference each other, causing a stack overflow and crashing the process.

Detection Guidance

This vulnerability is specific to the excelize library and requires checking if your application uses versions 2.8.1 to 2.11.0. Inspect Go module files for the excelize dependency version. No direct network detection commands exist as it is a library-level issue.

Impact Analysis

An attacker could exploit this by embedding two Excel formulas that reference each other in a workbook. When processed, this causes a stack overflow, crashing the application or service using Excelize. It affects any system evaluating formulas on untrusted data, including services using AddPivotTable or AddPicture.

Compliance Impact

This vulnerability could lead to denial-of-service attacks, disrupting services that handle sensitive data. For GDPR, this may impact availability of systems processing personal data. For HIPAA, it could affect systems managing protected health information by causing unexpected outages. Compliance may require patching or mitigating the risk to ensure service continuity.

Mitigation Strategies

Immediately stop using excelize versions 2.8.1 to 2.11.0. If possible, update to a patched version once available. Avoid processing untrusted Excel files with formula evaluation features until the issue is resolved.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107216. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart