Skip to main content

CVE-2026-107217: CWE-190: Integer Overflow or Wraparound in qax-os excelize

0
High
Published: 10/07/2026 (10/07/2026, 20:23:31 UTC)
Source: CVE Database V5
Vendor/Project: qax-os
Product: excelize

Description

### Summary `ColumnNameToNumber` (lib.go:220-237) accumulates the bijective base-26 value of a column name in an int64 with only an upper-bound check (`col > MaxColumns`) applied after the loop and no overflow detection. A 14-letter column name whose true value is 3·2⁶⁴ — e.g. **`VGWQHXLSDVIKWV`** — wraps to `col = 0` and passes the guard, so `CellNameToCoordinates("VGWQHXLSDVIKWV1")` returns `(col=0, row=1, err=nil)`. When normalizing a `r="0"` row, `checkSheetR0` (excelize.go:417-443, called from `checkSheet` at excelize.go:405) runs its `checkRow` closure with `col = 0`: `colIdx := col - 1` becomes **-1**, and `sheetData.Row[rowIdx].C[-1]` (excelize.go:424) raises an unrecovered `panic: runtime error: index out of range [-1]`, killing the host process. ### Details - The row side of the same coordinate gate is enforced (`checkRowNum` at excelize.go:342-350 bounds `r` before the `make([]xlsxRow, row)` allocation; this includes the fix for GHSA-h69g-9hx6-f3v4 / CVE-2026-54063, present in the audited commit). The **column** side is not: `checkSheet`/`lastRowNum`/`checkSheetR0` treat `err == nil` from `CellNameToCoordinates` as proof of an in-domain coordinate (excelize.go:356, :438), which is unsound because of the wrap-around above. - The same unsound gate also feeds `ws.SheetData.Row[rowIdx].C[colNum-1]` in `xlsxWorksheet.checkRow` (rows.go:969): a row combining a valid large column (e.g. `XFD1`) with an overflowed column panics identically. - Reachable from any `workSheetReader`-based API on an attacker-supplied worksheet: `GetCellValue`, `GetCellFormula`, `SetCellValue`, `GetMergeCells`, `GetSheetDimension`, `GetColWidth`, `AddTable`, etc. - Probe on pristine master: `ColumnNameToNumber("VGWQHXLSDVIKWV")` returns `(0, nil)`. - This is a distinct root cause from GHSA-h69g-9hx6-f3v4 (row-index allocation): different mechanism (int64 wrap-around → negative index, not oversized allocation), different sink, different fix. ### PoC A standalone program (public API only) was provided to the maintainer by email (`3-column-overflow`): it builds a workbook in memory whose `xl/worksheets/sheet1.xml` contains `<sheetData><row r="0"><c r="VGWQHXLSDVIKWV1" t="inlineStr"><is><t>pwn</t></is></c></row></sheetData>` (<1 KB of attacker XML), calls `OpenReader`, then `GetCellValue("Sheet1", "A1")` → `PANIC_REPRODUCED: runtime error: index out of range [-1]` on master `ecd99d761fe0` (2026-09-08). With the proposed patch the same program prints `NO_PANIC_BLOCKED`. ### Impact A <1 KB crafted `.xlsx` crashes any service that opens a user-supplied spreadsheet and reads it — upload processing, mail-scanning pipelines, spreadsheet conversion endpoints. Remote, unauthenticated, no privileges. ### Proposed fix Bound the accumulated value inside the loop: check `col > MaxColumns` after each digit. Every digit is at least 1, so any name whose true value exceeds MaxColumns crosses the bound inside the loop, before the accumulation can wrap or overflow — this provably covers all cases, including wraps that would land back inside `[1, MaxColumns]`. A complete patch has been provided to the maintainer.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

qax-os

excelize

Affected versions
>=2.0.0 <=2.11.0>=1.1.0 <=1.4.1
github.com/qax-os/excelize
pkg:golang/github.com/qax-os/excelize
Affected versions
>=1.1.0 <=1.4.1>=2.0.0 <=2.11.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 19:05:48 UTC

Technical Analysis

Excelize versions from 2.0.0 to 2.11.0 and from 1.1.0 to 1.4.1 contain an integer overflow in the ColumnNameToNumber function, which converts Excel column names to numeric indices. The function accumulates a bijective base-26 value in an int64 without detecting overflow, allowing a crafted long column name (e.g., VGWQHXLSDVIKWV) to wrap to zero silently. Subsequent functions checkSheetR0 and xlsxWorksheet.checkRow use this wrapped zero value as an index, which becomes a negative slice index during worksheet normalization. This triggers a panic that terminates the process using the library. As of the latest review, no patch or fixed version is available.

Potential Impact

An attacker can craft an Excel worksheet with a specially crafted long column name that triggers an integer overflow in the library. This causes the library to panic and terminate the calling process, resulting in a denial of service. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild.

Mitigation Recommendations

No fixed version or patch is currently available for this vulnerability. Users should avoid processing untrusted Excel files with affected versions of the Excelize library. Monitor the vendor's advisory channels for updates and patches addressing this issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-07T14:34:14.816Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac694282cdf04f65671beab

Added to database: 10/07/2026, 18:49:12 UTC

Last enriched: 10/07/2026, 19:05:48 UTC

Last updated: 10/07/2026, 21:55:06 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses