CVE-2026-107213

Source
https://cve.org/CVERecord?id=CVE-2026-107213
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107213.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107213
Aliases
Published
2026-10-07T17:40:29Z
Modified
2026-10-08T10:30:38Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but no drawing element
Details

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.9.0 to 2.11.0, GetSlicers checks for ExtLst but dereferences ws.Drawing without checking whether the independently optional drawing element exists. File.GetSlicers reads ws.Drawing.RID after seeing a worksheet extLst element even when the independently optional worksheet drawing element is absent. When a crafted worksheet contains an extLst element without a drawing element and the application calls GetSlicers, the nil ws.Drawing pointer is dereferenced while resolving the drawing relationship, allowing an attacker to panic and terminate an unprotected process. No fixed version is available as of this review.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-476"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107213.json"
}
References

Affected packages

Git / github.com/qax-os/excelize

Affected ranges

Type
GIT
Repo
https://github.com/qax-os/excelize
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.9.0"
        },
        {
            "last_affected": "2.11.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v2.*
v2.10.0
v2.10.1
v2.11.0
v2.9.0
v2.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107213.json"