CVE-2026-59161General(excelize / excelize)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch excelize excelize systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does not enforce the TotalRows limit on the row r attribute, allowing a small XLSX file with a row number above 1048576 and no cell coordinate to make GetRows append empty rows up to the attacker-controlled index and consume excessive memory and CPU. This issue is fixed in version 2.11.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • excelize

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
excelize

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-10: 2Patch / Workaround · 2026-07-10: 107-10
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-59161 Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does … https://www.cve.org/CVERecord?id=CVE-2026-59161 ----- Traducción: CVE-2026-59161 Exc… http://infoflow.cloud`

    Post summary

    The passage merely lists CVE‑2026‑59161 and a link to the CVE record, offering no further technical, exploit, or mitigation information.

    0000033
    91 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-59161 Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the streaming worksheet reader used by Rows and GetRows does … https://www.cve.org/CVERecord?id=CVE-2026-59161

    Post summary

    The post references CVE‑2026‑59161 affecting the Excelize Go library, noting that a fix is incorporated in version 2.11.0, but no PoC, exploit, or detailed technical data is provided.

    00000664
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appexcelizeexcelize-go-

Explore more