CVE-2026-107217
Awaiting Analysis Awaiting Analysis - Queue

Integer Overflow in Excelize Leading to Process Termination

Vulnerability report for CVE-2026-107217, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing name VGWQHXLSDVIKWV, after which checkSheetR0 and xlsxWorksheet.checkRow use the wrapped column value as an index. When a crafted worksheet uses an overflowing column name in a row normalized by checkSheetR0 or checkRow, the wrapped zero column becomes a negative slice index during worksheet normalization, allowing an attacker to panic and terminate the calling process. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-09
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
qax-os excelize >= 2.0.0, <= 2.11.0
qax-os excelize >= 1.1.0, <= 1.4.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CWE-129 The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an integer overflow flaw in the Excelize library's ColumnNameToNumber function. It occurs when processing large Excel column names like 'VGWQHXLSDVIKWV', which exceeds the maximum column limit. The function fails to detect overflow, causing the value to wrap to zero. This leads to invalid negative indices during worksheet normalization, triggering a runtime panic and denial-of-service when parsing untrusted Excel files.

Detection Guidance

Detecting this vulnerability requires checking if your system uses a vulnerable version of Excelize (1.1.0-1.4.1 or 2.0.0-2.11.0). Inspect Go module files for excelize dependencies and versions. No direct network detection commands exist, but you can scan applications using Excelize for crashes when processing malformed Excel files.

Impact Analysis

An attacker could exploit this by crafting a malicious Excel file with a large column name and specific row value. When processed, this would crash the application due to a negative slice index error. This could disrupt services relying on Excelize for spreadsheet parsing, potentially causing data processing failures or downtime.

Compliance Impact

This vulnerability could impact compliance by causing service disruptions or crashes when processing untrusted Excel files. For GDPR, this may affect data availability and integrity. For HIPAA, it could disrupt healthcare data processing systems. The lack of a fixed version exacerbates these risks as systems remain vulnerable.

Mitigation Strategies

Immediately upgrade to a patched version of Excelize if available. If no fixed version exists, avoid processing untrusted Excel files with applications using Excelize. Implement input validation for column names in your applications to reject excessively long names. Monitor for application crashes when handling spreadsheets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107217. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart