Disclosure summary
### Summary The `max` attribute of a `` element in `xl/worksheets/sheetN.xml` is read verbatim on open with no check against `MaxColumns`, and `flatCols()` then walks `Min..Max` doing a `deepcopy.Copy` and `append` per iteration. Executed: `max="300000"`, only about 18x past the real 16384 limit, cost 46.2 s of CPU and 122 MB on a single `SetColWidth` call, and the growth is linear in `max` up to 2^31-1. Confirmed at `ae2113b` (HEAD at the time of audit). ### Details `col.go:547`, `flatCols()`, with the two loops at `:549` and `:564`: ```go for i := col.Min; i
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-fq3v-74gv-27gm
Open original source · Updated Oct 07, 2026
Excelize: Unbounded attribute is loaded with no MaxColumns check and expanded per-column by flatCols(), so any column mutator hangs or OOMs the process
Source severity: HIGH / 7.1
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/xuri/excelize/v2 | >= 2.1.0, < 2.11.1-0.20260807015645-a54c578af309 | 2.11.1-0.20260807015645-a54c578af309 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T16:22:49-04:00
MODIFIED 2026-10-07T16:22:52-04:00
INGESTED 2026-10-08T12:30:38-04:00