{"id":"CVE-2026-107218","title":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets","summary":"Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with UTF-16 code-unit counts but slices a rune array using Unicode code-point counts. RIG…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-129"],"vendor":"xuri","product":"github.com/xuri/excelize/v2","affected":["github.com/xuri/excelize/v2 >= 2.10.1, < 2.11.1-0.20260908032718-ecd99d761fe0"],"patched":["github.com/xuri/excelize/v2 2.11.1-0.20260908032718-ecd99d761fe0"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:17:34.120","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107218","references":[{"url":"https://github.com/qax-os/excelize/commit/ecd99d761fe0489f1ed308e2f7dc2e0502d1a396","label":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/pull/2390","label":"security-advisories@github.com"},{"url":"https://github.com/qax-os/excelize/security/advisories/GHSA-8jjq-8j9w-m2v6","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-8jjq-8j9w-m2v6"}],"tags":["nvd","ghsa","go","cve.org"],"aliases":["GHSA-8jjq-8j9w-m2v6"],"ecosystem":"go","ingestedAt":"2026-10-07T20:46:46.976Z","slug":"CVE-2026-107218","body":"## Overview\n\nExcelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with UTF-16 code-unit counts but slices a rune array using Unicode code-point counts. RIGHT reaches leftRight through CalcCellValue, where countUTF16String validates one unit but utf8.RuneCountInString supplies the slice index in another. When RIGHT evaluates supplementary-plane text with a requested character count between the rune count and UTF-16 code-unit count, the inconsistent units produce a negative rune-slice index, allowing an attacker to panic during formula evaluation. No fixed version is available as of this review.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107218)\n\nAffected packages:\n\n- `github.com/xuri/excelize/v2 >= 2.10.1, < 2.11.1-0.20260908032718-ecd99d761fe0`\n\nPatched in:\n\n- `github.com/xuri/excelize/v2 2.11.1-0.20260908032718-ecd99d761fe0`\n\nSource: https://github.com/advisories/GHSA-8jjq-8j9w-m2v6","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}