CVE-2026-54063General(excelize / excelize)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch excelize excelize systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet() function in github.com/xuri/excelize/v2 uses an attacker-controlled <row r="N"> XML attribute value directly as the length argument to make([]xlsxRow, row) without validating it against the Excel row limit (TotalRows = 1,048,576). A specially crafted XLSX file can trigger two denial-of-service variants: (A) an out-of-memory process kill when r=2147483647 forces a ~16 GB allocation attempt, and (B) a runtime panic via out-of-bounds slice indexing when r=-1. Any service that opens attacker-supplied XLSX files and calls GetCellValue is affected. No authentication is required. This issue is fixed in version 2.11.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • excelize

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-07-10); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
excelize

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-10: 3Mentions · 2026-07-11: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-10: 2Technical Details · 2026-07-11: 107-1007-11
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-103
Disclosure1General2
2026-07-111
Patch1
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - Excelize XLSX row attribute slice allocation DoS (CVE-2026-54063) Excelize (http://github.com/xuri/excelize/v2) before 2.11.0 fails to validate an attacker-controlled XLSX XML row attribute before using it as the length for a slice allocation in checkSheet(). The root cause is improper input validation leading to unsafe slice allocation and potential out-of-bounds indexing. An attacker can exploit this by supplying a crafted XLSX file that triggers the vulnerable parsing path when a target processes it (e.g., calling GetCellValue), with no authentication or special privileges required. Successful exploitation results in denial of service via out-of-memory allocation attempts or a runtime panic that crashes the application. 👉 Affected: http://github.com/xuri/excelize/v2 < 2.11.0 | Upgrade to 2.11.0

    Post summary

    Excelize prior to version 2.11.0 is vulnerable to a DoS resulting from improper validation of XLSX row attributes; upgrading to 2.11.0 mitigates the issue.

    0000095
    247 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Excelize, Unbounded Row Index Allocation, #CVE-2026-54063 (HIGH) -DC-Jul2026-859 https://dailycve.com/excelize-unbounded-row-index-allocation-cve-2026-54063-high-dc-jul2026-859/

    Post summary

    The post announces a new high‑severity CVE (CVE-2026-54063) affecting Excelize, highlighting an unbounded row index allocation vulnerability.

    0000047
    218 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-54063 Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet() function in http://github.com/xuri/excelize/v2 uses… https://www.cve.org/CVERecord?id=CVE-2026-54063 ----- Traducción: CVE-2026-54063 Exceliz… http://infoflow.cloud`

    Post summary

    A brief notice of CVE-2026-54063 for the Excelize Go library, pointing out a pre‑2.11.0 issue with checkSheet() and linking to the CVE record, but providing no further technical or mitigation details.

    0000034
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-54063 Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet() function in http://github.com/xuri/excelize/v2 uses… https://www.cve.org/CVERecord?id=CVE-2026-54063

    Post summary

    The text highlights a vulnerability in the Go Excelize library before version 2.11.0, mentioning the affected function and providing a repository link, but offers no exploitation details, patch, or PoC information.

    00000828
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appexcelizeexcelize-go-

Explore more