AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-107214.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7.5CVSS 3.1 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSUndergoing AnalysisModified Oct 08, 2026

Disclosure summary

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or agileDecrypt before validating the structures used by those routines. When a malformed OLE compound file with a version-valid EncryptionInfo stream is opened or passed to Decrypt, nine malformed-input classes reach unrecovered Go runtime panics instead of the documented error path, allowing an attacker to terminate the calling process. No fixed version is available as of this review.

Source-reported weakness categories

CWE-248

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-107214

Open original source · Updated Oct 08, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

GitHub Reviewed Security Advisories · GHSA-2j4c-ffch-9f23

Open original source · Updated Oct 08, 2026

Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
gogithub.com/xuri/excelize/v2>= 2.3.1, < 2.11.1-0.20260915055537-22f76f9acb942.11.1-0.20260915055537-22f76f9acb94

Original records & references

PUBLISHED 2026-10-07T14:17:19-04:00
MODIFIED 2026-10-08T16:33:41-04:00
INGESTED 2026-10-10T20:50:46-04:00