CVE-2026-107222: Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no length or nil check
Summary
GetConditionalFormats reads sub-elements of a <cfRule> straight out of xl/worksheets/sheetN.xml and indexes them without checking length, and in one case without checking for nil. Three rule types are affected: cellIs, dataBar and colorScale. A workbook with a rule that is missing a child a real Excel file would always have panics the call.
Where it is
All three sinks are in styles.go, at the same line numbers in v2.11.0 and on master d552a7e. All three are reached from GetConditionalFormats through styles.go:3271.
styles.go:3003, in extractCondFmtCellIs:
go format.Value = c.Formula[0]
The branch above it handles len(c.Formula) == 2; this one is the fallback and does not check that there is a formula at all, so a cellIs rule with no <formula> child indexes an empty slice.
styles.go:3132, in the colorScale extractor:
go values := len(c.ColorScale.Cfvo)
c.ColorScale is a xlsxColorScale and is nil when the <cfRule type="colorScale"> element has no <colorScale> child. Lines 3148 and 3153 then index Cfvo[1] and Cfvo[2] in the three-colour branch with no length check either.
styles.go:3186, :3188 and :3190, in the dataBar extractor:
go format.MinType = c.DataBar.Cfvo[0].Type ... format.BarColor = "#" + f.getThemeColor(c.DataBar.Color[0])
The guard here is c.DataBar != nil, which says nothing about the length of Cfvo or Color, so an empty <dataBar></dataBar> element reaches all three.
Who the attacker is
Anyone who can hand a spreadsheet to a service that opens it and calls GetConditionalFormats. No authentication, no user interaction beyond the service doing its normal job, and the file is small.
Reproduction
Three minimal .xlsx files were built, each a real zip with [ContentTypes].xml, rels/.rels, xl/workbook.xml, xl/rels/workbook.xml.rels and one worksheet, opened each with the public excelize.OpenReader and called GetConditionalFormats("Sheet1"). Nothing internal is touched.
The worksheet fragment for the cellIs case, note there is no <formula> child:
xml <conditionalFormatting sqref="A1"><cfRule type="cellIs" operator="equal" priority="1" dxfId="0"/></conditionalFormatting>
for dataBar:
xml <conditionalFormatting sqref="A1"><cfRule type="dataBar" priority="1"><dataBar></dataBar></cfRule></conditionalFormatting>
and for colorScale:
xml <conditionalFormatting sqref="A1"><cfRule type="colorScale" priority="1"/></conditionalFormatting>
Observed against master d552a7e on go1.26.5:
text cellIs panic: runtime error: index out of range [0] with length 0 styles.go:3003 styles.go:1217 styles.go:3271
dataBar panic: runtime error: index out of range [0] with length 0 styles.go:3186 styles.go:1262 styles.go:3271
colorScale panic: runtime error: invalid memory address or nil pointer dereference styles.go:3132 styles.go:1259 styles.go:3271
One honesty note on impact. These are ordinary Go panics, not fatal errors, so a caller that wraps the call in recover survives them.
Suggested fix
Length-check c.Formula before line 3003 and return the rule with an empty value when there is no formula. Nil-check c.ColorScale before line 3132 and length-check ColorScale.Cfvo before indexing 1 and 2. Length-check DataBar.Cfvo and DataBar.Color alongside the existing nil check at 3186 to 3190. Skipping the malformed rule rather than erroring would keep GetConditionalFormats usable on files that are merely sloppy.
Affected versions
github.com/xuri/excelize/v2 up to and including v2.11.0, and master at d552a7e. I read the three sinks at tag v2.11.0 and at master and ran the reproducers against master.
Other sources
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.0 to 2.11.0, conditional-format extraction indexes required child slices or dereferences an optional colorScale child without validating malformed rule structure. GetConditionalFormats reaches extractCondFmtCellIs and also indexes ColorScale.Cfvo, DataBar.Cfvo, and DataBar.Color without complete structural checks. When a crafted worksheet supplies a cellIs, dataBar, or colorScale rule missing expected children and the application calls GetConditionalFormats, missing formula, color, value-object, or colorScale data reaches an out-of-range index or nil dereference, allowing an attacker to panic and terminate an unprotected process. No fixed version is available as of this review.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/xuri/excelize/v2to a version that resolves this vulnerability.Fixed in 2.11.1-0.20260812075026-be7a16390fa6 - Compensating control
Harden Excelize's conditional-format extraction by validating rule structure before indexing or dereferencing: check len(c.Formula) before accessing c.Formula[0] in extractCondFmtCellIs and return the rule with an empty value when absent; check c.ColorScale for nil and validate ColorScale.Cfvo before accessing indexes 1 and 2; and validate DataBar.Cfvo and DataBar.Color lengths in addition to the existing c.DataBar nil check. Skip malformed rules rather than allowing GetConditionalFormats to panic.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using Excelize versions 2.7.0 through 2.11.0 are exposed if they call GetConditionalFormats on worksheets supplied by an attacker or otherwise containing malformed conditional-formatting rules.
What must an attacker do to trigger the failure?
An attacker needs to provide a crafted worksheet with a malformed cellIs, dataBar, or colorScale conditional-formatting rule. The application must then process it by calling GetConditionalFormats; no attacker privileges are required, but user interaction is required according to the supplied vector.
What is the practical impact?
Malformed rule elements can cause an out-of-range index or nil-pointer dereference, panicking and terminating an unprotected process. The provided impact is limited to availability; no confidentiality or integrity impact is indicated.
Is a fixed version available?
No fixed version was available as of the review. Until a fix is available, avoid calling GetConditionalFormats on untrusted workbooks or isolate the parsing operation so a panic cannot terminate the main process.