Skip to main content

CVE-2026-107219: CWE-400: Uncontrolled Resource Consumption in qax-os excelize

0
High
Published: 10/07/2026 (10/07/2026, 20:23:22 UTC)
Source: CVE Database V5
Vendor/Project: qax-os
Product: excelize

Description

Opening a file whose first eight bytes are the OLE magic number sends excelize down the decryption path whether or not the caller set a password, or supports encrypted workbooks at all. `openReaderAt` (excelize.go:198-215) branches on the header alone, and `agileDecrypt` calls `convertPasswdToKey` before the verifier hash is checked, so the key-derivation loop runs `spinCount` times regardless. `spinCount` (crypt.go:98) is a plain `int` filled by a bare `xml.Unmarshal` of the file's own EncryptionInfo stream. Nothing bounds it. A 3072-byte file with spinCount 100000000 makes `OpenFile` take 58.65s on v2.11.0 with default options, then return `zip: not a valid zip file`. It is linear at about 0.6 microseconds per iteration and the attacker picks the number, so 1e9 is roughly ten minutes. Nothing on the path takes a `context.Context`, so the caller cannot cancel it; in an HTTP handler the write timeout returns a response while the goroutine keeps spinning. Memory stays flat at 24 MB, so nothing reclaims it either. ``` v2.5.0 spinCount=10000000 5.307s v2.9.1 spinCount=10000000 5.444s v2.11.0 spinCount=10000000 7.529s v2.11.0 spinCount=100000000 58.654s ``` The loop arrived with `crypt.go` in v2.3.1 and is unchanged through v2.11.0. Excel and LibreOffice write spinCount 100000, which costs 61ms here, so a ceiling well above the legitimate value would cost real files nothing. This is availability only, and it is not a vulnerability for a program that only opens files its own operator produced.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

qax-os

excelize

Affected versions
>=2.3.1 <=2.11.0
github.com/qax-os/excelize
pkg:golang/github.com/qax-os/excelize
Affected versions
>=2.3.1 <=2.11.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 19:06:00 UTC

Technical Analysis

Excelize is a Go library for reading and writing Excel files. Between versions 2.3.1 and 2.11.0, the agile decryption process accepts a spinCount parameter from the encrypted workbook header that controls the number of password-key derivation iterations. This spinCount is attacker-controlled and unbounded. When OpenFile calls agileDecrypt, it passes this spinCount to convertPasswdToKey, which performs the key derivation loop. If the spinCount is excessively large, the loop consumes CPU resources indefinitely without cancellation, leading to uncontrolled resource consumption (CWE-400). This can cause a denial of service by tying up a CPU core for an attacker-specified time. No fixed version or patch is available as of the review date.

Potential Impact

The vulnerability allows an unauthenticated attacker to cause a denial of service by opening a specially crafted encrypted Excel file with an excessive spinCount value. This results in unbounded CPU consumption on the victim system, potentially degrading performance or causing service disruption. There is no impact on confidentiality or integrity reported. The CVSS v3.1 score is 7.5 (High) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.

Mitigation Recommendations

No official fix or patch is currently available for this vulnerability. Users should avoid opening untrusted or suspicious encrypted Excel files with the affected versions of excelize (>=2.3.1 <=2.11.0) until a patch is released. Monitor vendor advisories for updates. No other mitigations are specified by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-07T14:34:14.816Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac694282cdf04f65671bead

Added to database: 10/07/2026, 18:49:12 UTC

Last enriched: 10/07/2026, 19:06:00 UTC

Last updated: 10/07/2026, 21:55:07 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses