---
id: CVE-2026-107218
title: >-
  Excelize is a Go language library for reading and writing Microsoft Excel
  spreadsheets
summary: >-
  Excelize is a Go language library for reading and writing Microsoft Excel
  spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with
  UTF-16 code-unit counts but slices a rune array using Unicode code-point
  counts. RIG…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-129
vendor: xuri
product: github.com/xuri/excelize/v2
affected:
  - >-
    github.com/xuri/excelize/v2 >= 2.10.1, <
    2.11.1-0.20260908032718-ecd99d761fe0
patched:
  - github.com/xuri/excelize/v2 2.11.1-0.20260908032718-ecd99d761fe0
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:34.120'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107218'
references:
  - url: >-
      https://github.com/qax-os/excelize/commit/ecd99d761fe0489f1ed308e2f7dc2e0502d1a396
    label: security-advisories@github.com
  - url: 'https://github.com/qax-os/excelize/pull/2390'
    label: security-advisories@github.com
  - url: 'https://github.com/qax-os/excelize/security/advisories/GHSA-8jjq-8j9w-m2v6'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-8jjq-8j9w-m2v6'
tags:
  - nvd
  - ghsa
  - go
  - cve.org
aliases:
  - GHSA-8jjq-8j9w-m2v6
ecosystem: go
ingestedAt: '2026-10-07T20:46:46.976Z'
---

## Overview

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.10.1 to 2.11.0, RIGHT validates the requested length with UTF-16 code-unit counts but slices a rune array using Unicode code-point counts. RIGHT reaches leftRight through CalcCellValue, where countUTF16String validates one unit but utf8.RuneCountInString supplies the slice index in another. When RIGHT evaluates supplementary-plane text with a requested character count between the rune count and UTF-16 code-unit count, the inconsistent units produce a negative rune-slice index, allowing an attacker to panic during formula evaluation. No fixed version is available as of this review.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107218)

Affected packages:

- `github.com/xuri/excelize/v2 >= 2.10.1, < 2.11.1-0.20260908032718-ecd99d761fe0`

Patched in:

- `github.com/xuri/excelize/v2 2.11.1-0.20260908032718-ecd99d761fe0`

Source: https://github.com/advisories/GHSA-8jjq-8j9w-m2v6
