GHSA-jrfj-fhj2-jjvm

Suggest an improvement
Source
https://github.com/advisories/GHSA-jrfj-fhj2-jjvm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-jrfj-fhj2-jjvm/GHSA-jrfj-fhj2-jjvm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jrfj-fhj2-jjvm
Aliases
  • CVE-2026-107219
Published
2026-10-07T20:23:22Z
Modified
2026-10-07T20:30:05Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Excelize: Unbounded spinCount in agile decryption burns CPU during OpenFile
Details

Opening a file whose first eight bytes are the OLE magic number sends excelize down the decryption path whether or not the caller set a password, or supports encrypted workbooks at all. openReaderAt (excelize.go:198-215) branches on the header alone, and agileDecrypt calls convertPasswdToKey before the verifier hash is checked, so the key-derivation loop runs spinCount times regardless.

spinCount (crypt.go:98) is a plain int filled by a bare xml.Unmarshal of the file's own EncryptionInfo stream. Nothing bounds it.

A 3072-byte file with spinCount 100000000 makes OpenFile take 58.65s on v2.11.0 with default options, then return zip: not a valid zip file. It is linear at about 0.6 microseconds per iteration and the attacker picks the number, so 1e9 is roughly ten minutes. Nothing on the path takes a context.Context, so the caller cannot cancel it; in an HTTP handler the write timeout returns a response while the goroutine keeps spinning. Memory stays flat at 24 MB, so nothing reclaims it either.

v2.5.0   spinCount=10000000   5.307s
v2.9.1   spinCount=10000000   5.444s
v2.11.0  spinCount=10000000   7.529s
v2.11.0  spinCount=100000000  58.654s

The loop arrived with crypt.go in v2.3.1 and is unchanged through v2.11.0.

Excel and LibreOffice write spinCount 100000, which costs 61ms here, so a ceiling well above the legitimate value would cost real files nothing.

This is availability only, and it is not a vulnerability for a program that only opens files its own operator produced.

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T20:23:22Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

Go / github.com/xuri/excelize/v2

Package

Name
github.com/xuri/excelize/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/xuri/excelize/v2

Affected ranges

Type
SEMVER
Events
Introduced
2.3.1
Fixed
2.11.1-0.20260906004932-2badfcd5841d

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-jrfj-fhj2-jjvm/GHSA-jrfj-fhj2-jjvm.json"