๐Ÿ” CVE Alert

CVE-2026-107211

UNKNOWN 0.0

Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverable panic

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks. extractPivotTableFields uses getPivotCacheFieldsName output while processing GetPivotTables and trusts the dataField fld attribute as an index. When a crafted workbook supplies a pivot-field count mismatch or an out-of-range dataField fld value before GetPivotTables is called, the unchecked index causes a Go slice-bounds panic that escapes the library, allowing an attacker to crash the process or request worker. No fixed version is available as of this review.

CWE CWE-129
Vendor qax-os
Product excelize
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for qax-os excelize

Be the first to know when new unknown vulnerabilities affecting qax-os excelize are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

qax-os / excelize
>= 2.8.1, <= 2.11.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/qax-os/excelize/security/advisories/GHSA-mx22-3794-2vpv github.com: https://github.com/qax-os/excelize/pull/2435 github.com: https://github.com/qax-os/excelize/commit/6258dcebc4e2a2aed985c38a08098dfd908521d1