๐Ÿ” CVE Alert

CVE-2026-107218

MEDIUM 5.3

Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with UTF-16 code-unit counts but slices a rune array using Unicode code-point counts. RIGHT reaches leftRight through CalcCellValue, where countUTF16String validates one unit but utf8.RuneCountInString supplies the slice index in another. When RIGHT evaluates supplementary-plane text with a requested character count between the rune count and UTF-16 code-unit count, the inconsistent units produce a negative rune-slice index, allowing an attacker to panic during formula evaluation. No fixed version is available as of this review.

CWE CWE-129
Vendor qax-os
Product excelize
Published Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for qax-os excelize

Be the first to know when new medium vulnerabilities affecting qax-os excelize are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected Versions

qax-os / excelize
>= 2.10.1, <= 2.11.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/qax-os/excelize/security/advisories/GHSA-8jjq-8j9w-m2v6 github.com: https://github.com/qax-os/excelize/pull/2390 github.com: https://github.com/qax-os/excelize/commit/ecd99d761fe0489f1ed308e2f7dc2e0502d1a396