PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107222 qax-os CVE debrief

CVE-2026-107222 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs in the GetConditionalFormats function, which indexes conditional-formatting rule sub-elements without validating the malformed rule structure. This can cause a panic and terminate an unprotected process when a crafted worksheet is supplied.

Vendor
qax-os
Product
excelize
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders who use the Excelize library in their applications should care about this vulnerability, as it can cause a denial-of-service (DoS) attack. Defenders should prioritize verifying the Excelize library version and applying a fix if available. Operators of platforms using Excelize should review their exposure and implement compensating controls for exposed systems while remediation is scheduled and verified. Security teams should monitor for potential

Why it matters

The vulnerability in the Excelize library can cause a denial-of-service (DoS) attack, allowing an attacker to panic and terminate an unprotected process. Defenders should prioritize verifying the Excelize library version and applying a fix if available.

  • Denial-of-service (DoS) attack
  • Potential panic and termination of an unprotected process

Technical summary

The GetConditionalFormats function in the Excelize library indexes conditional-formatting rule sub-elements without validating the malformed rule structure. This can cause a panic and terminate an unprotected process when a crafted worksheet is supplied. The vulnerability occurs in the GetConditionalFormats function, which indexes required child slices or dereferences an optional colorScale child without validating the malformed rule structure. Defenders should prioritize verifying the Excelize library version and applying a fix if available, as the vulnerability can cause a denial-of-service (DoS) attack.

Defensive priority

Defenders should prioritize verifying the Excelize library version and applying a fix if available, as the vulnerability can cause a denial-of-service (DoS) attack.

Recommended defensive actions

  • Verify the Excelize library version and apply a fix if available
  • Implement input validation and error handling for the GetConditionalFormats function
  • Monitor for potential DoS attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is caused by the GetConditionalFormats function indexing required child slices or dereferencing an optional colorScale child without validating the malformed rule structure. This can cause a panic and terminate an unprotected process when a crafted worksheet is supplied.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107222 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107222

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107222 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107222

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no length

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107222.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/qax-os/excelize/security/advisories/GHSA-rxcj-4pj5-74gr

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/qax-os/excelize/pull/2375

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/qax-os/excelize/commit/be7a16390fa69c71d3ca618c741d1a2b5ed362cd

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.