---
id: CVE-2026-107217
title: >-
  Excelize is a Go language library for reading and writing Microsoft Excel
  spreadsheets
summary: >-
  Excelize is a Go language library for reading and writing Microsoft Excel
  spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from
  1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a
  bijective b…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-129
  - CWE-190
vendor: xuri
product: github.com/xuri/excelize/v2
affected:
  - 'github.com/xuri/excelize/v2 >= 2.0.0, < 2.11.1-0.20260910071107-696050fbf14e'
  - 'github.com/xuri/excelize >= 1.1.0, <= 1.4.1'
patched:
  - github.com/xuri/excelize/v2 2.11.1-0.20260910071107-696050fbf14e
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:33.957'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107217'
references:
  - url: >-
      https://github.com/qax-os/excelize/commit/696050fbf14e74e96a58eef2b16aaf72f381a6a8
    label: security-advisories@github.com
  - url: 'https://github.com/qax-os/excelize/pull/2394'
    label: security-advisories@github.com
  - url: 'https://github.com/qax-os/excelize/security/advisories/GHSA-c85p-xxjj-2r75'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-c85p-xxjj-2r75'
tags:
  - nvd
  - ghsa
  - go
  - cve.org
aliases:
  - GHSA-c85p-xxjj-2r75
ecosystem: go
ingestedAt: '2026-10-07T20:46:46.975Z'
---

## Overview

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing name VGWQHXLSDVIKWV, after which checkSheetR0 and xlsxWorksheet.checkRow use the wrapped column value as an index. When a crafted worksheet uses an overflowing column name in a row normalized by checkSheetR0 or checkRow, the wrapped zero column becomes a negative slice index during worksheet normalization, allowing an attacker to panic and terminate the calling process. No fixed version is available as of this review.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107217)

Affected packages:

- `github.com/xuri/excelize/v2 >= 2.0.0, < 2.11.1-0.20260910071107-696050fbf14e`
- `github.com/xuri/excelize >= 1.1.0, <= 1.4.1`

Patched in:

- `github.com/xuri/excelize/v2 2.11.1-0.20260910071107-696050fbf14e`

Source: https://github.com/advisories/GHSA-c85p-xxjj-2r75
