AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-107223.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7.1CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Summary The `max` attribute of a `` element in `xl/worksheets/sheetN.xml` is read verbatim on open with no check against `MaxColumns`, and `flatCols()` then walks `Min..Max` doing a `deepcopy.Copy` and `append` per iteration. Executed: `max="300000"`, only about 18x past the real 16384 limit, cost 46.2 s of CPU and 122 MB on a single `SetColWidth` call, and the growth is linear in `max` up to 2^31-1. Confirmed at `ae2113b` (HEAD at the time of audit). ### Details `col.go:547`, `flatCols()`, with the two loops at `:549` and `:564`: ```go for i := col.Min; i

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-fq3v-74gv-27gm

Open original source · Updated Oct 07, 2026

Excelize: Unbounded attribute is loaded with no MaxColumns check and expanded per-column by flatCols(), so any column mutator hangs or OOMs the process

Source severity: HIGH / 7.1

EcosystemPackageAffected rangeFirst patched
gogithub.com/xuri/excelize/v2>= 2.1.0, < 2.11.1-0.20260807015645-a54c578af3092.11.1-0.20260807015645-a54c578af309

Original records & references

PUBLISHED 2026-10-07T16:22:49-04:00
MODIFIED 2026-10-07T16:22:52-04:00
INGESTED 2026-10-08T12:30:38-04:00