Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8jjq-8j9w-m2v6 | Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics |
Wed, 07 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qax-os
Qax-os excelize |
|
| Vendors & Products |
Qax-os
Qax-os excelize |
Wed, 07 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with UTF-16 code-unit counts but slices a rune array using Unicode code-point counts. RIGHT reaches leftRight through CalcCellValue, where countUTF16String validates one unit but utf8.RuneCountInString supplies the slice index in another. When RIGHT evaluates supplementary-plane text with a requested character count between the rune count and UTF-16 code-unit count, the inconsistent units produce a negative rune-slice index, allowing an attacker to panic during formula evaluation. No fixed version is available as of this review. | |
| Title | Excelize: RIGHT() on supplementary-plane text slices with a negative index and panics | |
| Weaknesses | CWE-129 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T22:05:36.155Z
Reserved: 2026-10-07T14:34:14.816Z
Link: CVE-2026-107218
Updated: 2026-10-07T22:03:47.687Z
Status : Received
Published: 2026-10-07T19:17:34.120
Modified: 2026-10-07T19:17:34.120
Link: CVE-2026-107218
No data.
OpenCVE Enrichment
Updated: 2026-10-07T20:00:12Z
-
CWE-129
Improper Validation of Array Index
Github GHSA