PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107211 qax-os CVE debrief

CVE-2026-107211 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks in the extractPivotTableFields function. This allows an attacker to crash the process or request worker by supplying a crafted workbook with a pivot-field count mismatch or an out-of-range dataField fld value.

Vendor
qax-os
Product
excelize
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for maintaining and securing systems that utilize the Excelize library should be aware of this vulnerability and take necessary actions to prevent potential crashes or worker requests.

Why it matters

CVE-2026-107211 is a vulnerability in the Excelize library that can cause process crashes or worker requests. Defenders should verify the library version, apply patches, and validate user-supplied workbooks to prevent exploitation.

  • Potential process crashes or worker requests due to unchecked pivot-cache field indices
  • Need for verification of Excelize library version and application of available patches
  • Importance of validating user-supplied workbooks for potential pivot-field count mismatches or out-of-range dataField fld values

Technical summary

The Excelize library, used for reading and writing Microsoft Excel spreadsheets in Go, is vulnerable to an unchecked pivot-cache field index in the extractPivotTableFields function. This occurs because separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks. An attacker can exploit this by supplying a crafted workbook with a pivot-field count mismatch or an out-of-range dataField fld value, causing a Go slice-bounds panic that escapes the library. This allows the attacker to crash the process or request worker. Defenders should prioritize verifying the Excelize library version and applying any available patches to prevent potential crashes or worker  

Defensive priority

Defenders should prioritize verifying the Excelize library version and applying any available patches to prevent potential crashes or worker requests.

Recommended defensive actions

  • Verify the Excelize library version and apply any available patches
  • Validate user-supplied workbooks for potential pivot-field count mismatches or out-of-range dataField fld values
  • Implement bounds checks when indexing the pivot-cache field-name slice
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is caused by a lack of bounds checks when indexing the pivot-cache field-name slice. This can be exploited by supplying a crafted workbook with a pivot-field count mismatch or an out-of-range dataField fld value.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107211 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107211

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107211 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107211

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Excelize: Unchecked pivot-cache field index in extractPivotTableFields causes unrecoverable pani

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107211.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/qax-os/excelize/security/advisories/GHSA-mx22-3794-2vpv

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/qax-os/excelize/pull/2435

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/qax-os/excelize/commit/6258dcebc4e2a2aed985c38a08098dfd908521d1

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.