CVE-2026-107223
Received Received - Intake

Memory Exhaustion in Excelize via Unbounded Column Width

Vulnerability report for CVE-2026-107223, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, flatCols expands file-loaded column ranges without validating Min and Max against the worksheet column limit. SetColWidth reaches flatCols, which expands xlsxCol.Min through xlsxCol.Max without enforcing MaxColumns. When a crafted worksheet supplies an oversized col max attribute and the application invokes a column mutator, flatCols performs a deep copy and append for every attacker-selected column number, allowing an attacker to consume excessive CPU and memory or trigger OOM. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
qax-os excelize >= 2.1.0, <= 2.11.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Excelize Go library (versions 2.1.0 to 2.11.0) involves improper handling of column ranges in Excel files. When a crafted spreadsheet contains an excessively large 'max' column attribute, the flatCols function processes columns from Min to Max without validating against the worksheet's column limit (16,384). This causes deep copies and appends for each column, leading to excessive CPU and memory consumption or triggering out-of-memory conditions.

Detection Guidance

Detecting this vulnerability requires checking if your system uses the vulnerable excelize library versions (2.1.0 to 2.11.0). Inspect Go module dependencies for 'github.com/qax-os/excelize' and verify the version. No direct network detection commands are provided in the context.

Impact Analysis

If you process untrusted Excel files using affected versions of Excelize, an attacker could craft a file that consumes excessive system resources. This may cause your application to slow down significantly, hang, or crash due to high CPU usage or memory exhaustion. It could disrupt services relying on Excel file processing.

Compliance Impact

This vulnerability could lead to denial-of-service or out-of-memory conditions when processing maliciously crafted Excel files, potentially disrupting services that handle sensitive data. For GDPR, this may impact availability of systems processing personal data. For HIPAA, it could affect the integrity and availability of protected health information systems.

Mitigation Strategies

Immediately upgrade to excelize v2.11.1 or later if using versions 2.1.0 to 2.11.0. Avoid processing untrusted Excel files until patched. Validate input files for excessively large column ranges before processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107223. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart