PatchSiren

qax-os CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH qax-os CVE published 2026-10-08

CVE-2026-107211

CVE-2026-107211 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks in the extractPivotTableFields function. This allows an attacker to crash the process or request worker by supplying [truncated]

HIGH qax-os CVE published 2026-10-08

CVE-2026-107212

CVE-2026-107212 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when the Rows.Columns function accepts a look-ahead row number above TotalRows without applying the limit enforced by Rows.Next. This can cause the GetRows function and the Rows iterator to loop for an extended period, allowing an attacke [truncated]

HIGH qax-os CVE published 2026-10-08

CVE-2026-107213

CVE-2026-107213 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when a worksheet has an extLst present but no drawing element, causing a nil-pointer dereference in the GetSlicers function. This can lead to a panic and terminate an unprotected process.

HIGH qax-os CVE published 2026-10-08

CVE-2026-107214

CVE-2026-107214 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when the decryption dispatch performs insufficient structural and parameter validation before standard and agile decryptors slice, index, allocate, and divide using attacker-controlled values. This can cause unrecoverable panics on malfor [truncated]

HIGH qax-os CVE published 2026-10-08

CVE-2026-107215

CVE-2026-107215 is a high-severity vulnerability in the Excelize library, which allows for remote denial-of-service (DoS) attacks due to unbounded and negative-sized buffer allocations. The vulnerability exists in versions 2.3.1 to 2.11.0 of the library. This issue arises from the extractPart function allocating a byte slice directly from an attacker-controlled CFB directory-entry size before validating t [truncated]

MEDIUM qax-os CVE published 2026-10-07

CVE-2026-107218

CVE-2026-107218 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when the RIGHT() function is used on supplementary-plane text slices with a negative index, causing a panic during formula evaluation. The vulnerability affects versions 2.10.1 to 2.11.0 of the Excelize library.

HIGH qax-os CVE published 2026-10-07

CVE-2026-107219

CVE-2026-107219 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when the library attempts to decrypt an OLE encrypted-workbook header with an attacker-controlled spinCount, leading to unbounded CPU consumption. This can be triggered when a crafted OLE encrypted-workbook header supplies an excessive sp [truncated]

MEDIUM qax-os CVE published 2026-10-07

CVE-2026-107220

CVE-2026-107220 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when the mergeCellsParser leaves the cached rectangle empty for an empty mergeCell ref and then passes that empty slice to cellInRange without a length check. This allows an attacker to panic on the first affected cell operation when a cr [truncated]

MEDIUM qax-os CVE published 2026-10-07

CVE-2026-107221

CVE-2026-107221 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when a crafted row places a higher-column cell before a lower-column final cell and a non-streaming worksheet API reads the sheet, causing an unrecovered panic and terminating the process.

HIGH qax-os CVE published 2026-10-07

CVE-2026-107223

CVE-2026-107223 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when the library expands file-loaded column ranges without validating Min and Max against the worksheet column limit. This can cause a denial-of-service (DoS) attack when a crafted worksheet supplies an oversized col max attribute and the [truncated]

MEDIUM qax-os CVE published 2026-10-07

CVE-2026-107224

A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader in Excelize, a Go library for reading and writing Microsoft Excel spreadsheets. Versions 2.1.0 to 2.11.0 are affected. The vulnerability occurs because the Zip64 uncompressed size with the high bit set is converted from uint64 to a negative int64 before signed size-limit checks and allocation. This can cause a panic when opening a specially craf [truncated]

MEDIUM qax-os CVE published 2026-10-07

CVE-2026-107225

CVE-2026-107225 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs when the GetStyle function is called with a crafted styles.xml file that contains a negative fillId, borderId, or fontId. This causes the function to panic while reading cell styling. The vulnerability affects versions 2.8.0 to 2.11.0 of [truncated]

MEDIUM qax-os CVE published 2026-10-07

CVE-2026-107222

CVE-2026-107222 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs in the GetConditionalFormats function, which indexes conditional-formatting rule sub-elements without validating the malformed rule structure. This can cause a panic and terminate an unprotected process when a crafted worksheet is supplied.

HIGH qax-os CVE published 2026-10-07

CVE-2026-107217

CVE-2026-107217 is a vulnerability in the Excelize library, which is a Go language library for reading and writing Microsoft Excel spreadsheets. The vulnerability occurs in the ColumnNameToNumber function, which accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. This can cause a negative slice index panic during wo [truncated]

MEDIUM qax-os CVE published 2026-07-10

CVE-2026-59162

CVE-2026-59162 is a vulnerability in Excelize, a Go library for reading and writing Microsoft Excel spreadsheets. Prior to version 2.11.0, Excelize does not properly handle shared-string cell values, allowing an attacker to trigger a panic when reading a malformed XLSX file through the GetCellValue or GetRows functions. The vulnerability exists because Excelize uses strconv.Atoi to parse shared-string cel [truncated]

HIGH qax-os CVE published 2026-07-10

CVE-2026-59161

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-10T17:17:02.250Z and has not been modified since then. The Excelize library, used for reading and writing Microsoft Excel spreadsheets in Go, had a vulnerability prior to version 2.11.0. This vulnerability allows a small XLSX file with a row number above 1048576 and no cell coordinate to make GetRow [truncated]

HIGH qax-os CVE published 2026-07-10

CVE-2026-54063

CVE-2026-54063 is a denial-of-service vulnerability in Excelize, a Go library for reading and writing Microsoft Excel spreadsheets. The vulnerability exists in the checkSheet() function, which uses an attacker-controlled XML attribute value directly as the length argument to make([]xlsxRow, row) without validating it against the Excel row limit (TotalRows = 1,048,576). A specially crafted XLSX file can tr [truncated]