CVE-2026-107214: Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or agileDecrypt before validating the structures used by those routines. When a malformed OLE compound file with a version-valid EncryptionInfo stream is opened or passed to Decrypt, nine malformed-input classes reach unrecovered Go runtime panics instead of the documented error path, allowing an attacker to terminate the calling process. No fixed version is available as of this review.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using Excelize versions 2.3.1 through 2.11.0 are exposed if they open encrypted Excel workbooks or pass attacker-controlled EncryptionInfo and EncryptedPackage data to Decrypt. An unauthenticated remote attacker can trigger the condition by supplying a malformed OLE compound file with a version-valid EncryptionInfo stream.
What is the practical impact of successful exploitation?
Successful exploitation causes an unrecovered Go runtime panic in the calling process, resulting in denial of service. The provided data identifies availability impact only; it does not indicate confidentiality or integrity impact.
Are malformed files rejected safely?
No. Nine malformed-input classes can reach standardDecrypt or agileDecrypt before the required structures and parameters are validated, causing panics rather than the documented error path.
Is a fixed release available?
No fixed version was available as of the review. Organizations should treat untrusted encrypted workbooks as potentially service-terminating input until a fix is available or deployed.