CVE-2026-107221: CWE-787: Out-of-bounds Write in qax-os excelize
Description
## Affected versions and vulnerable location - Confirmed at `ae2113b` (current HEAD). - Sink: `rows.go:967` `ws.SheetData.Row[rowIdx].C[colNum-1] = *colData` inside `checkRow`. - `checkRow` computes `lastCol` from the column of the last cell in document order (`rows.go:940`), allocates `targetList` of that length, then re-scatters every source cell into `C[colNum-1]`. ## Root cause The slice is sized from the last cell's column, but cells are not required to be column-sorted in the XML. A cell that appears earlier in the row but references a higher column than the last cell has `colNum-1 >= len(targetList)`, so the assignment writes out of range. `MaxColumns`/`TotalRows` do not help, every individual column is valid; the bug is the ordering assumption, not magnitude. ## Attacker model and reachability Any service that opens an untrusted spreadsheet and calls a worksheet API that goes through `workSheetReader -> checkRow` (`excelize.go:332`): `GetCellValue`, `GetCellFormula`, `CalcCellValue`, `GetMergeCells`, `SetCellValue`, and essentially every non-streaming worksheet call. (The streaming `GetRows`/`Rows()` SAX path does not trigger it.) Unauthenticated, deterministic, unrecovered panic -> process crash. ## Proof of concept (executed) Crafted `xl/worksheets/sheet1.xml` with a row whose cells are out of column order and whose earlier cell exceeds the last cell's column: ```xml <row r="1"><c r="D1"><v>4</v></c><c r="C1"><v>3</v></c></row> ``` `GetCellValue("Sheet1","A1")` (via `getCellStringFunc -> workSheetReader -> checkRow`) panicked `index out of range [3] with length 3` at `rows.go:967`. Confirming grep: ```bash rg -n "func checkRow|lastCol|Row\[rowIdx\].C\[colNum-1\]" rows.go ``` ## Suggested fix Size `targetList` from the maximum cell column in the row (not the last cell in document order), or bounds-check `colNum-1` against `len(targetList)` and grow the slice as needed before the assignment.
CVSS v3.1
Score 6.5medium
Affected software
qax-os
excelize
pkg:golang/github.com/qax-os/excelizeRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Excelize is a Go library for handling Microsoft Excel spreadsheets. Versions from 2.0.0 up to and including 2.11.0 contain a vulnerability (CWE-787) in the checkRow function. The function sizes a target cell slice based on the last cell's column index in XML document order, then re-scatters cells by their explicit column references. If a crafted row places a higher-column cell before a lower-column final cell, the earlier cell's column index can exceed the slice length, causing an out-of-bounds write. This triggers an unrecovered panic that terminates the process when using a non-streaming worksheet API. No fixed version is available as of the latest review.
Potential Impact
The vulnerability can cause a denial of service by triggering an unrecovered panic that terminates the process reading the spreadsheet. There is no impact on confidentiality or integrity reported. No known exploits are in the wild.
Mitigation Recommendations
No official fix or patch is currently available. Users should avoid processing untrusted or crafted Excel files with the affected versions of Excelize, especially using the non-streaming worksheet API. Monitor vendor advisories for updates on remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-07T14:34:14.816Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac694282cdf04f65671beaf
Added to database: 10/07/2026, 18:49:12 UTC
Last enriched: 10/07/2026, 19:06:16 UTC
Last updated: 10/07/2026, 21:55:07 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.