CVE-2026-107215: Excelize: extractPart allocates attacker-controlled, unbounded and negative-sized buffers from CFB directory entries: remote panic / OOM DoS

Published Oct 7, 2026
·
Updated

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or size domain. extractPart trusts the CFB directory entry streamSize for EncryptionInfo and EncryptedPackage allocations before validating the stream. When a crafted OLE compound file declares a negative or extremely large EncryptionInfo or EncryptedPackage stream size, the declared size reaches make with a negative length or forces a multi-gigabyte allocation, allowing an attacker to panic or exhaust process memory. No fixed version is available as of this review.

Affected Software

1 affected component
Excelize Excelize>=2.3.1<=2.11.0

Event History

Oct 7, 2026
CVE Published
via MITRE·05:48 PM
Data Sourced
via MITRE·05:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this denial-of-service issue?

Applications using Excelize versions 2.3.1 through 2.11.0 to process attacker-controlled or otherwise untrusted OLE compound Excel files are exposed. The affected parsing path handles EncryptionInfo and EncryptedPackage streams.

2

What does an attacker need to exploit it?

An attacker needs to provide a crafted OLE compound file with a negative or extremely large directory-entry streamSize for EncryptionInfo or EncryptedPackage. Exploitation does not require authentication or user interaction according to the supplied vector.

3

What happens when a malicious file is processed?

The library can pass the declared stream size directly to a byte-slice allocation before validating the stream. A negative size can panic the process, while an extremely large size can consume multi-gigabyte memory and cause an out-of-memory denial of service.

4

Is a fixed version available?

No fixed version was available as of this review. The provided references include an upstream pull request and commit related to the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203