---
id: CVE-2026-107220
title: >-
  Excelize is a Go language library for reading and writing Microsoft Excel
  spreadsheets
summary: >-
  Excelize is a Go language library for reading and writing Microsoft Excel
  spreadsheets. From 2.7.1 to 2.11.0, mergeCellsParser leaves the cached
  rectangle empty for an empty mergeCell ref and then passes that empty slice to
  cellInRange w…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-125
  - CWE-129
vendor: xuri
product: github.com/xuri/excelize/v2
affected:
  - 'github.com/xuri/excelize/v2 >= 2.7.1, < 2.11.1-0.20260820023833-99903a3240e5'
patched:
  - github.com/xuri/excelize/v2 2.11.1-0.20260820023833-99903a3240e5
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:34.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107220'
references:
  - url: >-
      https://github.com/qax-os/excelize/commit/99903a3240e58a47ff28fb8e05a03bd9d496ec24
    label: security-advisories@github.com
  - url: 'https://github.com/qax-os/excelize/pull/2379'
    label: security-advisories@github.com
  - url: 'https://github.com/qax-os/excelize/security/advisories/GHSA-g27h-8qhm-6pff'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-g27h-8qhm-6pff'
tags:
  - nvd
  - ghsa
  - go
  - cve.org
aliases:
  - GHSA-g27h-8qhm-6pff
ecosystem: go
ingestedAt: '2026-10-07T20:46:46.976Z'
---

## Overview

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.1 to 2.11.0, mergeCellsParser leaves the cached rectangle empty for an empty mergeCell ref and then passes that empty slice to cellInRange without a length check. GetCellValue reaches mergeCellsParser, which passes an empty rectangle derived from the mergeCell ref attribute into cellInRange. When a crafted worksheet contains an empty mergeCell ref and a non-streaming cell API reads the worksheet, cellInRange indexes four positions in an empty slice, allowing an attacker to panic on the first affected cell operation. No fixed version is available as of this review.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107220)

Affected packages:

- `github.com/xuri/excelize/v2 >= 2.7.1, < 2.11.1-0.20260820023833-99903a3240e5`

Patched in:

- `github.com/xuri/excelize/v2 2.11.1-0.20260820023833-99903a3240e5`

Source: https://github.com/advisories/GHSA-g27h-8qhm-6pff
