CVE-2026-107211
Last modified
CVE-2026-107211 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks.
Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks. extractPivotTableFields uses getPivotCacheFieldsName output while processing GetPivotTables and trusts the dataField fld attribute as an index. When a crafted workbook supplies a pivot-field count mismatch or an out-of-range dataField fld value before GetPivotTables is called, the unchecked index causes a Go slice-bounds panic that escapes the library, allowing an attacker to crash the process or request worker. No fixed version is available as of this review.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| qax-os | excelize | >= 2.8.1, <= 2.11.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-107211?
How severe is CVE-2026-107211?
How do I fix CVE-2026-107211?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107206LMCache through 0.5.5 contains a missing authentication vuln…9.4
- CVE-2026-107207LMCache through 0.5.5 contains a server-side request forgery…7.2
- CVE-2026-107208ImageMagick is free and open-source software used for editin…5.3
- CVE-2026-107209ImageMagick is free and open-source software used for editin…5.9
- CVE-2026-10721Concrete CMS below 9.5.2 is vulnerable to PHP Object Injecti…8.4
- CVE-2026-107210ImageMagick is free and open-source software used for editin…5.3
- CVE-2026-107212Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107213Excelize is a Go language library for reading and writing Mi…8.7
- CVE-2026-107214Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107215Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107216Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107217Excelize is a Go language library for reading and writing Mi…7.5
Are you affected by CVE-2026-107211?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
