
🚨 HIGH - Excelize XLSX row attribute slice allocation DoS (CVE-2026-54063) Excelize (http://github.com/xuri/excelize/v2) before 2.11.0 fails to validate an attacker-controlled XLSX XML row attribute before using it as the length for a slice allocation in checkSheet(). The root cause is improper input validation leading to unsafe slice allocation and potential out-of-bounds indexing. An attacker can exploit this by supplying a crafted XLSX file that triggers the vulnerable parsing path when a target processes it (e.g., calling GetCellValue), with no authentication or special privileges required. Successful exploitation results in denial of service via out-of-memory allocation attempts or a runtime panic that crashes the application. 👉 Affected: http://github.com/xuri/excelize/v2 < 2.11.0 | Upgrade to 2.11.0
Post summary
Excelize prior to version 2.11.0 is vulnerable to a DoS resulting from improper validation of XLSX row attributes; upgrading to 2.11.0 mitigates the issue.



