
🚨High - Excelize OLE/CFB Stream Size DoS via Unbounded Allocation (CVE-2026-107215) In http://github.com/xuri/excelize/v2, the extractPart function allocates a buffer directly from the stream size field of an attacker-controlled CFB directory entry, with no bounds check. The underlying CFB parser only detects mismatched stream lengths after the allocation has already happened. A crafted OLE/CFB compound file (the format used for encrypted workbooks) can declare a negative or massive stream size, causing a panic or multi-GB allocation that crashes the process or triggers OOM. Any service that automatically processes untrusted Excel uploads with Excelize is exposed. 👉Affected: http://github.com/xuri/excelize/v2 2.3.1 – 2.11.0 (fix available only as commit 5f636f9, no tagged release yet)
