Disclosure summary
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks. extractPivotTableFields uses getPivotCacheFieldsName output while processing GetPivotTables and trusts the dataField fld attribute as an index. When a crafted workbook supplies a pivot-field count mismatch or an out-of-range dataField fld value before GetPivotTables is called, the unchecked index causes a Go slice-bounds panic that escapes the library, allowing an attacker to crash the process or request worker. No fixed version is available as of this review.
Source-reported weakness categories
CWE-129
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107211
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-mx22-3794-2vpv
Open original source · Updated Oct 08, 2026
Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverable panic
Source severity: HIGH / 8.7
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/xuri/excelize/v2 | >= 2.8.1, < 2.11.1-0.20261003002531-6258dcebc4e2 | 2.11.1-0.20261003002531-6258dcebc4e2 |
Original records & references
PUBLISHED 2026-10-07T14:17:18-04:00
MODIFIED 2026-10-08T16:33:41-04:00
INGESTED 2026-10-10T20:50:46-04:00