Disclosure summary
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, Rows.Columns accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. File.GetRows relies on Rows.Next and Rows.Columns, but Rows.Columns consumes the row r attribute without the limit check in Rows.Next. When a crafted worksheet places an oversized row number after an ordinary valid row and the application calls GetRows or iterates Rows, the iterator advances through every missing row number instead of rejecting the workbook, allowing an attacker to consume a CPU core for an attacker-controlled duration. No fixed version is available as of this review.
Source-reported weakness categories
CWE-770
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107212
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-jw42-f3rr-4cc3
Open original source · Updated Oct 08, 2026
Excelize: Unbounded row number in Rows.Columns makes GetRows and the Rows iterator loop for days
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/xuri/excelize/v2 | >= 2.1.0, < 2.11.1-0.20260930021559-01a9ff32fb3c | 2.11.1-0.20260930021559-01a9ff32fb3c |
Original records & references
PUBLISHED 2026-10-07T14:17:18-04:00
MODIFIED 2026-10-08T16:33:41-04:00
INGESTED 2026-10-10T20:50:46-04:00