CVE-2026-107214
Last modified
CVE-2026-107214 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values.
Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or agileDecrypt before validating the structures used by those routines. When a malformed OLE compound file with a version-valid EncryptionInfo stream is opened or passed to Decrypt, nine malformed-input classes reach unrecovered Go runtime panics instead of the documented error path, allowing an attacker to terminate the calling process. No fixed version is available as of this review.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| qax-os | excelize | >= 2.3.1, <= 2.11.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-107214?
How severe is CVE-2026-107214?
How do I fix CVE-2026-107214?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107209ImageMagick is free and open-source software used for editin…5.9
- CVE-2026-10721Concrete CMS below 9.5.2 is vulnerable to PHP Object Injecti…8.4
- CVE-2026-107210ImageMagick is free and open-source software used for editin…5.3
- CVE-2026-107211Excelize is a Go language library for reading and writing Mi…8.7
- CVE-2026-107212Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107213Excelize is a Go language library for reading and writing Mi…8.7
- CVE-2026-107215Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107216Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107217Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107218Excelize is a Go language library for reading and writing Mi…5.3
- CVE-2026-107219Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-10722A vulnerability has been found in cilium ebpf up to 0.21.0. …5.5
Are you affected by CVE-2026-107214?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
