CVE-2026-107217

Source
https://cve.org/CVERecord?id=CVE-2026-107217
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107217.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107217
Aliases
Published
2026-10-07T18:26:55Z
Modified
2026-10-08T10:45:28Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinate with nil error, causing negative slice index panic on r="0" rows
Details

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing name VGWQHXLSDVIKWV, after which checkSheetR0 and xlsxWorksheet.checkRow use the wrapped column value as an index. When a crafted worksheet uses an overflowing column name in a row normalized by checkSheetR0 or checkRow, the wrapped zero column becomes a negative slice index during worksheet normalization, allowing an attacker to panic and terminate the calling process. No fixed version is available as of this review.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-129",
        "CWE-190"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107217.json"
}
References

Affected packages

Git / github.com/qax-os/excelize

Affected ranges

Type
GIT
Repo
https://github.com/qax-os/excelize
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.11.0"
        },
        {
            "introduced": "1.1.0"
        },
        {
            "last_affected": "1.4.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.1.0
v1.2.0
v1.3.0
v1.4.0
v1.4.1
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.1.0
v2.10.0
v2.10.1
v2.11.0
v2.2.0
v2.3.0
v2.3.1
v2.3.2
v2.4.0
v2.4.1
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107217.json"