Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qax-os
Qax-os excelize |
|
| Vendors & Products |
Qax-os
Qax-os excelize |
|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks. extractPivotTableFields uses getPivotCacheFieldsName output while processing GetPivotTables and trusts the dataField fld attribute as an index. When a crafted workbook supplies a pivot-field count mismatch or an out-of-range dataField fld value before GetPivotTables is called, the unchecked index causes a Go slice-bounds panic that escapes the library, allowing an attacker to crash the process or request worker. No fixed version is available as of this review. | |
| Title | Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverable panic | |
| Weaknesses | CWE-129 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T19:03:18.640Z
Reserved: 2026-10-07T14:34:14.815Z
Link: CVE-2026-107211
Updated: 2026-10-07T19:03:09.508Z
Status : Received
Published: 2026-10-07T18:17:18.490
Modified: 2026-10-07T19:17:33.660
Link: CVE-2026-107211
No data.
OpenCVE Enrichment
Updated: 2026-10-07T20:15:17Z
-
CWE-129
Improper Validation of Array Index