PatchSiren cyber security CVE debrief
CVE-2026-107222 qax-os CVE debrief
CVE-2026-107222 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs in the GetConditionalFormats function, which indexes conditional-formatting rule sub-elements without validating the malformed rule structure. This can cause a panic and terminate an unprotected process when a crafted worksheet is supplied.
- Vendor
- qax-os
- Product
- excelize
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders who use the Excelize library in their applications should care about this vulnerability, as it can cause a denial-of-service (DoS) attack. Defenders should prioritize verifying the Excelize library version and applying a fix if available. Operators of platforms using Excelize should review their exposure and implement compensating controls for exposed systems while remediation is scheduled and verified. Security teams should monitor for potential
Why it matters
The vulnerability in the Excelize library can cause a denial-of-service (DoS) attack, allowing an attacker to panic and terminate an unprotected process. Defenders should prioritize verifying the Excelize library version and applying a fix if available.
- Denial-of-service (DoS) attack
- Potential panic and termination of an unprotected process
Technical summary
The GetConditionalFormats function in the Excelize library indexes conditional-formatting rule sub-elements without validating the malformed rule structure. This can cause a panic and terminate an unprotected process when a crafted worksheet is supplied. The vulnerability occurs in the GetConditionalFormats function, which indexes required child slices or dereferences an optional colorScale child without validating the malformed rule structure. Defenders should prioritize verifying the Excelize library version and applying a fix if available, as the vulnerability can cause a denial-of-service (DoS) attack.
Defensive priority
Defenders should prioritize verifying the Excelize library version and applying a fix if available, as the vulnerability can cause a denial-of-service (DoS) attack.
Recommended defensive actions
- Verify the Excelize library version and apply a fix if available
- Implement input validation and error handling for the GetConditionalFormats function
- Monitor for potential DoS attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability is caused by the GetConditionalFormats function indexing required child slices or dereferencing an optional colorScale child without validating the malformed rule structure. This can cause a panic and terminate an unprotected process when a crafted worksheet is supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107222 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107222
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107222 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107222
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Excelize: GetConditionalFormats indexes conditional-formatting rule sub-elements with no length
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107222.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/qax-os/excelize/security/advisories/GHSA-rxcj-4pj5-74gr
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/qax-os/excelize/pull/2375
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/qax-os/excelize/commit/be7a16390fa69c71d3ca618c741d1a2b5ed362cd
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.