CVE-2026-107219
Received Received - Intake

Heap Overflow in Excelize via Unbounded spinCount in Agile Decryption

Vulnerability report for CVE-2026-107219, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, agile decryption accepts an attacker-controlled spinCount and performs that many password-key derivation iterations before verifier validation. OpenFile reaches agileDecrypt, which passes the unbounded spinCount to convertPasswdToKey before password verification. When a crafted OLE encrypted-workbook header supplies an excessive spinCount and the file is opened, the key-derivation loop performs unbounded attacker-selected work and cannot be cancelled, allowing an attacker to consume a CPU core for an attacker-controlled duration. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qax-os excelize >= 2.3.1, <= 2.11.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Excelize, a Go library for reading and writing Excel files. It allows an attacker to provide a malicious spinCount value that forces excessive CPU usage during password key derivation before file verification. This causes the system to consume a CPU core indefinitely without proper validation.

Detection Guidance

This vulnerability involves excessive CPU usage due to unbounded spinCount in password key derivation during Excel file decryption. Detection requires monitoring for abnormal CPU usage spikes when processing Excel files, particularly those with crafted OLE encrypted-workbook headers. Check for processes running excelize or Go applications handling Excel files with high CPU consumption.

Impact Analysis

An attacker could exploit this by providing a specially crafted Excel file. Opening the file would cause high CPU usage, potentially leading to system slowdowns or denial of service. It does not directly expose data but disrupts normal operations.

Compliance Impact

This vulnerability primarily impacts system availability by enabling denial-of-service attacks through excessive CPU consumption. While it does not directly violate GDPR or HIPAA confidentiality or integrity requirements, it could indirectly affect compliance by degrading system performance, potentially disrupting access to personal or health data. Organizations relying on Excelize for processing sensitive data may face availability-related compliance issues if systems become unresponsive due to such attacks.

Mitigation Strategies

Immediate mitigation involves avoiding the use of affected Excelize versions (2.3.1 to 2.11.0) for processing untrusted Excel files. If possible, upgrade to a fixed version once available. As a temporary workaround, restrict access to Excel files from untrusted sources and monitor system resources for unusual CPU spikes during file processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107219. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart