Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qax-os
Qax-os excelize |
|
| Vendors & Products |
Qax-os
Qax-os excelize |
Wed, 07 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.9.0 to 2.11.0, GetSlicers checks for ExtLst but dereferences ws.Drawing without checking whether the independently optional drawing element exists. File.GetSlicers reads ws.Drawing.RID after seeing a worksheet extLst element even when the independently optional worksheet drawing element is absent. When a crafted worksheet contains an extLst element without a drawing element and the application calls GetSlicers, the nil ws.Drawing pointer is dereferenced while resolving the drawing relationship, allowing an attacker to panic and terminate an unprotected process. No fixed version is available as of this review. | |
| Title | Excelize: Nil-pointer dereference in GetSlicers when a worksheet has extLst present but no drawing element | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T17:40:29.865Z
Reserved: 2026-10-07T14:34:14.815Z
Link: CVE-2026-107213
No data.
Status : Received
Published: 2026-10-07T18:17:18.860
Modified: 2026-10-07T18:17:18.860
Link: CVE-2026-107213
No data.
OpenCVE Enrichment
Updated: 2026-10-07T20:15:17Z
-
CWE-476
NULL Pointer Dereference