CVE-2026-107214: Excelize Decrypt: unrecoverable panics on malformed OLE/CFB encrypted workbooks

Published Oct 7, 2026
·
Updated

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or agileDecrypt before validating the structures used by those routines. When a malformed OLE compound file with a version-valid EncryptionInfo stream is opened or passed to Decrypt, nine malformed-input classes reach unrecovered Go runtime panics instead of the documented error path, allowing an attacker to terminate the calling process. No fixed version is available as of this review.

Affected Software

1 affected component
Excelize Excelize>=2.3.1<=2.11.0

Event History

Oct 7, 2026
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using Excelize versions 2.3.1 through 2.11.0 are exposed if they open encrypted Excel workbooks or pass attacker-controlled EncryptionInfo and EncryptedPackage data to Decrypt. An unauthenticated remote attacker can trigger the condition by supplying a malformed OLE compound file with a version-valid EncryptionInfo stream.

2

What is the practical impact of successful exploitation?

Successful exploitation causes an unrecovered Go runtime panic in the calling process, resulting in denial of service. The provided data identifies availability impact only; it does not indicate confidentiality or integrity impact.

3

Are malformed files rejected safely?

No. Nine malformed-input classes can reach standardDecrypt or agileDecrypt before the required structures and parameters are validated, causing panics rather than the documented error path.

4

Is a fixed release available?

No fixed version was available as of the review. Organizations should treat untrusted encrypted workbooks as potentially service-terminating input until a fix is available or deployed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203