CVE-2026-107219: CWE-400: Uncontrolled Resource Consumption in qax-os excelize
Description
Opening a file whose first eight bytes are the OLE magic number sends excelize down the decryption path whether or not the caller set a password, or supports encrypted workbooks at all. `openReaderAt` (excelize.go:198-215) branches on the header alone, and `agileDecrypt` calls `convertPasswdToKey` before the verifier hash is checked, so the key-derivation loop runs `spinCount` times regardless. `spinCount` (crypt.go:98) is a plain `int` filled by a bare `xml.Unmarshal` of the file's own EncryptionInfo stream. Nothing bounds it. A 3072-byte file with spinCount 100000000 makes `OpenFile` take 58.65s on v2.11.0 with default options, then return `zip: not a valid zip file`. It is linear at about 0.6 microseconds per iteration and the attacker picks the number, so 1e9 is roughly ten minutes. Nothing on the path takes a `context.Context`, so the caller cannot cancel it; in an HTTP handler the write timeout returns a response while the goroutine keeps spinning. Memory stays flat at 24 MB, so nothing reclaims it either. ``` v2.5.0 spinCount=10000000 5.307s v2.9.1 spinCount=10000000 5.444s v2.11.0 spinCount=10000000 7.529s v2.11.0 spinCount=100000000 58.654s ``` The loop arrived with `crypt.go` in v2.3.1 and is unchanged through v2.11.0. Excel and LibreOffice write spinCount 100000, which costs 61ms here, so a ceiling well above the legitimate value would cost real files nothing. This is availability only, and it is not a vulnerability for a program that only opens files its own operator produced.
CVSS v3.1
Score 7.5high
Affected software
qax-os
excelize
pkg:golang/github.com/qax-os/excelizeRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Excelize is a Go library for reading and writing Excel files. Between versions 2.3.1 and 2.11.0, the agile decryption process accepts a spinCount parameter from the encrypted workbook header that controls the number of password-key derivation iterations. This spinCount is attacker-controlled and unbounded. When OpenFile calls agileDecrypt, it passes this spinCount to convertPasswdToKey, which performs the key derivation loop. If the spinCount is excessively large, the loop consumes CPU resources indefinitely without cancellation, leading to uncontrolled resource consumption (CWE-400). This can cause a denial of service by tying up a CPU core for an attacker-specified time. No fixed version or patch is available as of the review date.
Potential Impact
The vulnerability allows an unauthenticated attacker to cause a denial of service by opening a specially crafted encrypted Excel file with an excessive spinCount value. This results in unbounded CPU consumption on the victim system, potentially degrading performance or causing service disruption. There is no impact on confidentiality or integrity reported. The CVSS v3.1 score is 7.5 (High) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.
Mitigation Recommendations
No official fix or patch is currently available for this vulnerability. Users should avoid opening untrusted or suspicious encrypted Excel files with the affected versions of excelize (>=2.3.1 <=2.11.0) until a patch is released. Monitor vendor advisories for updates. No other mitigations are specified by the vendor.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-07T14:34:14.816Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac694282cdf04f65671bead
Added to database: 10/07/2026, 18:49:12 UTC
Last enriched: 10/07/2026, 19:06:00 UTC
Last updated: 10/07/2026, 21:55:07 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.