CVE-2026-107217
Last modified
CVE-2026-107217 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error.
Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing name VGWQHXLSDVIKWV, after which checkSheetR0 and xlsxWorksheet.checkRow use the wrapped column value as an index. When a crafted worksheet uses an overflowing column name in a row normalized by checkSheetR0 or checkRow, the wrapped zero column becomes a negative slice index during worksheet normalization, allowing an attacker to panic and terminate the calling process. No fixed version is available as of this review.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| qax-os | excelize | >= 2.0.0, <= 2.11.0; >= 1.1.0, <= 1.4.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-107217?
How severe is CVE-2026-107217?
How do I fix CVE-2026-107217?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107211Excelize is a Go language library for reading and writing Mi…8.7
- CVE-2026-107212Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107213Excelize is a Go language library for reading and writing Mi…8.7
- CVE-2026-107214Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107215Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107216Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-107218Excelize is a Go language library for reading and writing Mi…5.3
- CVE-2026-107219Excelize is a Go language library for reading and writing Mi…7.5
- CVE-2026-10722A vulnerability has been found in cilium ebpf up to 0.21.0. …5.5
- CVE-2026-107220Excelize is a Go language library for reading and writing Mi…6.5
- CVE-2026-107221Excelize is a Go language library for reading and writing Mi…6.5
- CVE-2026-107222Excelize is a Go language library for reading and writing Mi…6.5
Are you affected by CVE-2026-107217?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
