---
id: CVE-2026-107214
title: >-
  Excelize is a Go language library for reading and writing Microsoft Excel
  spreadsheets
summary: >-
  Excelize is a Go language library for reading and writing Microsoft Excel
  spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs
  insufficient structural and parameter validation before standard and agile
  decryptors slice, i…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-248
vendor: qax-os
product: excelize
affected:
  - 'excelize >= 2.3.1, <= 2.11.0'
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:19.040'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107214'
references:
  - url: >-
      https://github.com/qax-os/excelize/commit/22f76f9acb94b85b3eb9c4365ab4f750cebbc565
    label: security-advisories@github.com
  - url: 'https://github.com/qax-os/excelize/pull/2395'
    label: security-advisories@github.com
  - url: 'https://github.com/qax-os/excelize/security/advisories/GHSA-2j4c-ffch-9f23'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T18:42:20.891Z'
---

## Overview

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.3.1 to 2.11.0, the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. Decrypt passes attacker-controlled EncryptionInfo and EncryptedPackage data into standardDecrypt or agileDecrypt before validating the structures used by those routines. When a malformed OLE compound file with a version-valid EncryptionInfo stream is opened or passed to Decrypt, nine malformed-input classes reach unrecovered Go runtime panics instead of the documented error path, allowing an attacker to terminate the calling process. No fixed version is available as of this review.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
