PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107225 qax-os CVE debrief

CVE-2026-107225 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when the GetStyle function is called with a crafted styles.xml file that contains a negative fillId, borderId, or fontId. This causes the function to panic while reading cell styling. The vulnerability affects versions 2.8.0 to 2.11.0 of the Excelize library.

Vendor
qax-os
Product
excelize
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders who use the Excelize library in their applications should be aware of this vulnerability and take steps to verify the version of the library used and update to a fixed version as soon as it becomes available.

Why it matters

CVE-2026-107225 is a vulnerability in the Excelize library that could be used to launch a denial-of-service attack against applications using the library. Defenders should verify the version of the library used in their applications and update to a fixed version as soon as it becomes available.

  • An attacker could craft a malicious styles.xml file to cause the application to panic while reading cell styling.
  • The vulnerability could be used to launch a denial-of-service attack against applications using the Excelize library.
  • Defenders should verify the version of the Excelize library used in their applications and update to a fixed version as soon as it becomes available.

Technical summary

The Excelize library, used for reading and writing Microsoft Excel spreadsheets in Go, is vulnerable to a panic attack. This occurs when the GetStyle function is called with a crafted styles.xml file containing negative fillId, borderId, or fontId values. The vulnerability affects versions 2.8.0 to 2.11.0 of the library. An attacker could exploit this by providing a malicious styles.xml file, causing the application to panic while reading cell styling. Defenders should prioritize verifying the version of the Excelize library used in their applications and updating to a fixed version as soon as it becomes available.

Defensive priority

Defenders should prioritize verifying the version of the Excelize library used in their applications and updating to a fixed version as soon as it becomes available.

Recommended defensive actions

  • Verify the version of the Excelize library used in your application
  • Update to a fixed version as soon as it becomes available
  • Review and validate the styles.xml file for negative fillId, borderId, or fontId values
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The vulnerability is caused by the GetStyle function's failure to check for negative fillId, borderId, or fontId values in the styles.xml file. This allows an attacker to panic the application while reading cell styling.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107225 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107225

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107225 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107225

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Excelize: GetStyle panics on a negative fillId, borderId or fontId in styles.xml

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107225.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/qax-os/excelize/security/advisories/GHSA-5h23-36rv-pm65

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/qax-os/excelize/pull/2367

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/qax-os/excelize/commit/ae2113b410e51f6a141c396a59eda8c42b91bc22

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.