Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.0 to 2.11.0, GetStyle's fill, border, and font extraction predicates check only upper bounds for attacker-controlled style-table indices. File.GetStyle relies on extractStyleCondFuncs predicates that allow negative FillID, BorderID, and FontID values to reach slice indexing. When a crafted styles.xml supplies a negative fillId, borderId, or fontId and the application reads the style, a negative identifier passes the upper-bound-only predicate and becomes a negative slice index, allowing an attacker to panic while reading cell styling. No fixed version is available as of this review.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5h23-36rv-pm65 | Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qax-os
Qax-os excelize |
|
| Vendors & Products |
Qax-os
Qax-os excelize |
Wed, 07 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.0 to 2.11.0, GetStyle's fill, border, and font extraction predicates check only upper bounds for attacker-controlled style-table indices. File.GetStyle relies on extractStyleCondFuncs predicates that allow negative FillID, BorderID, and FontID values to reach slice indexing. When a crafted styles.xml supplies a negative fillId, borderId, or fontId and the application reads the style, a negative identifier passes the upper-bound-only predicate and becomes a negative slice index, allowing an attacker to panic while reading cell styling. No fixed version is available as of this review. | |
| Title | Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml | |
| Weaknesses | CWE-129 CWE-20 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T18:55:55.603Z
Reserved: 2026-10-07T14:34:14.816Z
Link: CVE-2026-107225
No data.
Status : Received
Published: 2026-10-07T19:17:35.333
Modified: 2026-10-07T19:17:35.333
Link: CVE-2026-107225
No data.
OpenCVE Enrichment
Updated: 2026-10-07T20:45:07Z
Github GHSA