
🚨High - Excelize Crafted XLSX Panic DoS (CVE-2026-107211, CVE-2026-107213) Two flaws in http://github.com/xuri/excelize/v2 let a crafted spreadsheet crash any Go process that reads it: CVE-2026-107211: GetPivotTables indexes the pivot-cache field list with attacker-controlled field indices from a separate pivot-table part, with no bounds check, causing an index-out-of-range panic. CVE-2026-107213: GetSlicers checks only that extLst exists, then dereferences the worksheet's drawing element without a nil check, causing a nil-pointer panic. 👉Affected: Excelize 2.8.1 – 2.11.0 (CVE-2026-107211), 2.9.0 – 2.11.0 (CVE-2026-107213). Fixed only in master commits, no tagged release yet.
