CVE-2026-107215

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, extractPart allocates a byte slice directly from an attacker-controlled CFB directory-entry size before validating the sector chain or size domain. extractPart trusts the CFB directory entry streamSize for EncryptionInfo and EncryptedPackage allocations before validating the stream. When a crafted OLE compound file declares a negative or extremely large EncryptionInfo or EncryptedPackage stream size, the declared size reaches make with a negative length or forces a multi-gigabyte allocation, allowing an attacker to panic or exhaust process memory. No fixed version is available as of this review.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-789

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Referenced assets2 URLs
By indicator
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨High - Excelize OLE/CFB Stream Size DoS via Unbounded Allocation (CVE-2026-107215) In http://github.com/xuri/excelize/v2, the extractPart function allocates a buffer directly from the stream size field of an attacker-controlled CFB directory entry, with no bounds check. The underlying CFB parser only detects mismatched stream lengths after the allocation has already happened. A crafted OLE/CFB compound file (the format used for encrypted workbooks) can declare a negative or massive stream size, causing a panic or multi-GB allocation that crashes the process or triggers OOM. Any service that automatically processes untrusted Excel uploads with Excelize is exposed. 👉Affected: http://github.com/xuri/excelize/v2 2.3.1 – 2.11.0 (fix available only as commit 5f636f9, no tagged release yet)

    0001050
    315 followersView on X

Explore more