Disclosure summary
## Summary `GetConditionalFormats` reads sub-elements of a `` straight out of `xl/worksheets/sheetN.xml` and indexes them without checking length, and in one case without checking for nil. Three rule types are affected: `cellIs`, `dataBar` and `colorScale`. A workbook with a rule that is missing a child a real Excel file would always have panics the call. ## Where it is All three sinks are in `styles.go`, at the same line numbers in v2.11.0 and on master `d552a7e`. All three are reached from `GetConditionalFormats` through `styles.go:3271`. `styles.go:3003`, in `extractCondFmtCellIs`: ```go format.Value = c.Formula[0] ``` The branch above it handles `len(c.Formula) == 2`; this one is the fallback and does not check that there is a formula at all, so a `cellIs` rule with no `` child indexes an empty slice. `styles.go:3132`, in the colorScale extractor: ```go values := len(c.ColorScale.Cfvo) ``` `c.ColorScale` is a `*xlsxColorScale` and is nil when the `` element has no `` child. Lines 3148 and 3153 then index `Cfvo[1]` and `Cfvo[2]` in the three-colour branch with no length check either. `styles.go:3186`, `:3188` and `:3190`, in the dataBar extractor: ```go format.MinType = c.DataBa
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-rxcj-4pj5-74gr
Open original source · Updated Oct 07, 2026
Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no length or nil check
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/xuri/excelize/v2 | >= 2.7.0, < 2.11.1-0.20260812075026-be7a16390fa6 | 2.11.1-0.20260812075026-be7a16390fa6 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T16:22:54-04:00
MODIFIED 2026-10-07T16:22:57-04:00
INGESTED 2026-10-08T12:30:38-04:00