Skip to main content

CVE-2026-107221: CWE-787: Out-of-bounds Write in qax-os excelize

0
Medium
Published: 10/07/2026 (10/07/2026, 20:23:08 UTC)
Source: CVE Database V5
Vendor/Project: qax-os
Product: excelize

Description

## Affected versions and vulnerable location - Confirmed at `ae2113b` (current HEAD). - Sink: `rows.go:967` `ws.SheetData.Row[rowIdx].C[colNum-1] = *colData` inside `checkRow`. - `checkRow` computes `lastCol` from the column of the last cell in document order (`rows.go:940`), allocates `targetList` of that length, then re-scatters every source cell into `C[colNum-1]`. ## Root cause The slice is sized from the last cell's column, but cells are not required to be column-sorted in the XML. A cell that appears earlier in the row but references a higher column than the last cell has `colNum-1 >= len(targetList)`, so the assignment writes out of range. `MaxColumns`/`TotalRows` do not help, every individual column is valid; the bug is the ordering assumption, not magnitude. ## Attacker model and reachability Any service that opens an untrusted spreadsheet and calls a worksheet API that goes through `workSheetReader -> checkRow` (`excelize.go:332`): `GetCellValue`, `GetCellFormula`, `CalcCellValue`, `GetMergeCells`, `SetCellValue`, and essentially every non-streaming worksheet call. (The streaming `GetRows`/`Rows()` SAX path does not trigger it.) Unauthenticated, deterministic, unrecovered panic -> process crash. ## Proof of concept (executed) Crafted `xl/worksheets/sheet1.xml` with a row whose cells are out of column order and whose earlier cell exceeds the last cell's column: ```xml <row r="1"><c r="D1"><v>4</v></c><c r="C1"><v>3</v></c></row> ``` `GetCellValue("Sheet1","A1")` (via `getCellStringFunc -> workSheetReader -> checkRow`) panicked `index out of range [3] with length 3` at `rows.go:967`. Confirming grep: ```bash rg -n "func checkRow|lastCol|Row\[rowIdx\].C\[colNum-1\]" rows.go ``` ## Suggested fix Size `targetList` from the maximum cell column in the row (not the last cell in document order), or bounds-check `colNum-1` against `len(targetList)` and grow the slice as needed before the assignment.

CVSS v3.1

Score 6.5medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected software

qax-os

excelize

Affected versions
>=2.0.0 <=2.11.0
github.com/qax-os/excelize
pkg:golang/github.com/qax-os/excelize
Affected versions
>=2.0.0 <=2.11.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/07/2026, 19:06:16 UTC

Technical Analysis

Excelize is a Go library for handling Microsoft Excel spreadsheets. Versions from 2.0.0 up to and including 2.11.0 contain a vulnerability (CWE-787) in the checkRow function. The function sizes a target cell slice based on the last cell's column index in XML document order, then re-scatters cells by their explicit column references. If a crafted row places a higher-column cell before a lower-column final cell, the earlier cell's column index can exceed the slice length, causing an out-of-bounds write. This triggers an unrecovered panic that terminates the process when using a non-streaming worksheet API. No fixed version is available as of the latest review.

Potential Impact

The vulnerability can cause a denial of service by triggering an unrecovered panic that terminates the process reading the spreadsheet. There is no impact on confidentiality or integrity reported. No known exploits are in the wild.

Mitigation Recommendations

No official fix or patch is currently available. Users should avoid processing untrusted or crafted Excel files with the affected versions of Excelize, especially using the non-streaming worksheet API. Monitor vendor advisories for updates on remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-07T14:34:14.816Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac694282cdf04f65671beaf

Added to database: 10/07/2026, 18:49:12 UTC

Last enriched: 10/07/2026, 19:06:16 UTC

Last updated: 10/07/2026, 21:55:07 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses