CVE-2026-107217: CWE-190: Integer Overflow or Wraparound in qax-os excelize
Description
### Summary `ColumnNameToNumber` (lib.go:220-237) accumulates the bijective base-26 value of a column name in an int64 with only an upper-bound check (`col > MaxColumns`) applied after the loop and no overflow detection. A 14-letter column name whose true value is 3·2⁶⁴ — e.g. **`VGWQHXLSDVIKWV`** — wraps to `col = 0` and passes the guard, so `CellNameToCoordinates("VGWQHXLSDVIKWV1")` returns `(col=0, row=1, err=nil)`. When normalizing a `r="0"` row, `checkSheetR0` (excelize.go:417-443, called from `checkSheet` at excelize.go:405) runs its `checkRow` closure with `col = 0`: `colIdx := col - 1` becomes **-1**, and `sheetData.Row[rowIdx].C[-1]` (excelize.go:424) raises an unrecovered `panic: runtime error: index out of range [-1]`, killing the host process. ### Details - The row side of the same coordinate gate is enforced (`checkRowNum` at excelize.go:342-350 bounds `r` before the `make([]xlsxRow, row)` allocation; this includes the fix for GHSA-h69g-9hx6-f3v4 / CVE-2026-54063, present in the audited commit). The **column** side is not: `checkSheet`/`lastRowNum`/`checkSheetR0` treat `err == nil` from `CellNameToCoordinates` as proof of an in-domain coordinate (excelize.go:356, :438), which is unsound because of the wrap-around above. - The same unsound gate also feeds `ws.SheetData.Row[rowIdx].C[colNum-1]` in `xlsxWorksheet.checkRow` (rows.go:969): a row combining a valid large column (e.g. `XFD1`) with an overflowed column panics identically. - Reachable from any `workSheetReader`-based API on an attacker-supplied worksheet: `GetCellValue`, `GetCellFormula`, `SetCellValue`, `GetMergeCells`, `GetSheetDimension`, `GetColWidth`, `AddTable`, etc. - Probe on pristine master: `ColumnNameToNumber("VGWQHXLSDVIKWV")` returns `(0, nil)`. - This is a distinct root cause from GHSA-h69g-9hx6-f3v4 (row-index allocation): different mechanism (int64 wrap-around → negative index, not oversized allocation), different sink, different fix. ### PoC A standalone program (public API only) was provided to the maintainer by email (`3-column-overflow`): it builds a workbook in memory whose `xl/worksheets/sheet1.xml` contains `<sheetData><row r="0"><c r="VGWQHXLSDVIKWV1" t="inlineStr"><is><t>pwn</t></is></c></row></sheetData>` (<1 KB of attacker XML), calls `OpenReader`, then `GetCellValue("Sheet1", "A1")` → `PANIC_REPRODUCED: runtime error: index out of range [-1]` on master `ecd99d761fe0` (2026-09-08). With the proposed patch the same program prints `NO_PANIC_BLOCKED`. ### Impact A <1 KB crafted `.xlsx` crashes any service that opens a user-supplied spreadsheet and reads it — upload processing, mail-scanning pipelines, spreadsheet conversion endpoints. Remote, unauthenticated, no privileges. ### Proposed fix Bound the accumulated value inside the loop: check `col > MaxColumns` after each digit. Every digit is at least 1, so any name whose true value exceeds MaxColumns crosses the bound inside the loop, before the accumulation can wrap or overflow — this provably covers all cases, including wraps that would land back inside `[1, MaxColumns]`. A complete patch has been provided to the maintainer.
CVSS v3.1
Score 7.5high
Affected software
qax-os
excelize
pkg:golang/github.com/qax-os/excelizeRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Excelize versions from 2.0.0 to 2.11.0 and from 1.1.0 to 1.4.1 contain an integer overflow in the ColumnNameToNumber function, which converts Excel column names to numeric indices. The function accumulates a bijective base-26 value in an int64 without detecting overflow, allowing a crafted long column name (e.g., VGWQHXLSDVIKWV) to wrap to zero silently. Subsequent functions checkSheetR0 and xlsxWorksheet.checkRow use this wrapped zero value as an index, which becomes a negative slice index during worksheet normalization. This triggers a panic that terminates the process using the library. As of the latest review, no patch or fixed version is available.
Potential Impact
An attacker can craft an Excel worksheet with a specially crafted long column name that triggers an integer overflow in the library. This causes the library to panic and terminate the calling process, resulting in a denial of service. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild.
Mitigation Recommendations
No fixed version or patch is currently available for this vulnerability. Users should avoid processing untrusted Excel files with affected versions of the Excelize library. Monitor the vendor's advisory channels for updates and patches addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-07T14:34:14.816Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac694282cdf04f65671beab
Added to database: 10/07/2026, 18:49:12 UTC
Last enriched: 10/07/2026, 19:05:48 UTC
Last updated: 10/07/2026, 21:55:06 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.