PatchSiren cyber security CVE debrief
CVE-2026-107211 qax-os CVE debrief
CVE-2026-107211 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks in the extractPivotTableFields function. This allows an attacker to crash the process or request worker by supplying a crafted workbook with a pivot-field count mismatch or an out-of-range dataField fld value.
- Vendor
- qax-os
- Product
- excelize
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for maintaining and securing systems that utilize the Excelize library should be aware of this vulnerability and take necessary actions to prevent potential crashes or worker requests.
Why it matters
CVE-2026-107211 is a vulnerability in the Excelize library that can cause process crashes or worker requests. Defenders should verify the library version, apply patches, and validate user-supplied workbooks to prevent exploitation.
- Potential process crashes or worker requests due to unchecked pivot-cache field indices
- Need for verification of Excelize library version and application of available patches
- Importance of validating user-supplied workbooks for potential pivot-field count mismatches or out-of-range dataField fld values
Technical summary
The Excelize library, used for reading and writing Microsoft Excel spreadsheets in Go, is vulnerable to an unchecked pivot-cache field index in the extractPivotTableFields function. This occurs because separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks. An attacker can exploit this by supplying a crafted workbook with a pivot-field count mismatch or an out-of-range dataField fld value, causing a Go slice-bounds panic that escapes the library. This allows the attacker to crash the process or request worker. Defenders should prioritize verifying the Excelize library version and applying any available patches to prevent potential crashes or worker
Defensive priority
Defenders should prioritize verifying the Excelize library version and applying any available patches to prevent potential crashes or worker requests.
Recommended defensive actions
- Verify the Excelize library version and apply any available patches
- Validate user-supplied workbooks for potential pivot-field count mismatches or out-of-range dataField fld values
- Implement bounds checks when indexing the pivot-cache field-name slice
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is caused by a lack of bounds checks when indexing the pivot-cache field-name slice. This can be exploited by supplying a crafted workbook with a pivot-field count mismatch or an out-of-range dataField fld value.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107211 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107211
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107211 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107211
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverable pani
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107211.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/qax-os/excelize/security/advisories/GHSA-mx22-3794-2vpv
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/qax-os/excelize/pull/2435
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/qax-os/excelize/commit/6258dcebc4e2a2aed985c38a08098dfd908521d1
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.