| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fw94-4wwp-w8pw | Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 07 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qax-os
Qax-os excelize |
|
| Vendors & Products |
Qax-os
Qax-os excelize |
Wed, 07 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, a Zip64 uncompressed size with the high bit set is converted from uint64 to a negative int64 before signed size-limit checks and allocation. ReadZipReader obtains UncompressedSize64 through FileInfo.Size and passes the wrapped negative value to readFile. When a crafted Zip64 entry declares an uncompressed size from 2^63 through 2^64-1 and the workbook is opened, the negative size bypasses unzip limits and reaches make as a negative capacity, allowing an attacker to panic during workbook opening. No fixed version is available as of this review. | |
| Title | Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader | |
| Weaknesses | CWE-190 CWE-681 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T19:30:13.733Z
Reserved: 2026-10-07T14:34:14.816Z
Link: CVE-2026-107224
Updated: 2026-10-07T19:30:07.190Z
Status : Received
Published: 2026-10-07T19:17:35.140
Modified: 2026-10-07T20:17:11.713
Link: CVE-2026-107224
No data.
OpenCVE Enrichment
Updated: 2026-10-07T20:45:07Z
Github GHSA