CVE-2026-107213: CWE-476: NULL Pointer Dereference in qax-os excelize
Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.9.0 to 2.11.0, GetSlicers checks for ExtLst but dereferences ws.Drawing without checking whether the independently optional drawing element exists. File.GetSlicers reads ws.Drawing.RID after seeing a worksheet extLst element even when the independently optional worksheet drawing element is absent. When a crafted worksheet contains an extLst element without a drawing element and the application calls GetSlicers, the nil ws.Drawing pointer is dereferenced while resolving the drawing relationship, allowing an attacker to panic and terminate an unprotected process. No fixed version is available as of this review.
CVSS v4.0
Score 8.7high
Affected software
qax-os
excelize
pkg:golang/github.com/qax-os/excelizeRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in excelize arises because the GetSlicers function checks for the presence of an extLst element but dereferences the ws.Drawing pointer without confirming that the optional drawing element exists. Specifically, File.GetSlicers reads ws.Drawing.RID after detecting a worksheet extLst element, even if the drawing element is absent. This results in a NULL pointer dereference when processing a specially crafted worksheet, causing the application to panic and terminate unexpectedly.
Potential Impact
An attacker can cause a denial of service by triggering a NULL pointer dereference that crashes the application using the vulnerable excelize library. This impacts any unprotected process that calls GetSlicers on a maliciously crafted worksheet. There is no indication of code execution or data corruption beyond process termination.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should monitor the vendor advisory for updates. Until a fix is released, avoid processing untrusted Excel files with the affected versions of excelize or implement application-level protections to handle panics gracefully.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-07T14:34:14.815Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac686182cdf04f6566c0b2f
Added to database: 10/07/2026, 17:49:12 UTC
Last enriched: 10/07/2026, 18:03:18 UTC
Last updated: 10/07/2026, 22:34:01 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.