Answer in brief
CVE-2026-107217 records a High severity (CVSS 7.5) vulnerability in Excelize ColumnNameToNumber: int64 overflow yields an out-of-domain coordinate with nil error, causing negative slice index panic on r="0" rows. The current sources do not mark it as known exploited. The current feed maps qax-os/excelize (generic), github.com/xuri/excelize (go), github.com/xuri/excelize/v2 (go). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps qax-os/excelize (generic), github.com/xuri/excelize (go), github.com/xuri/excelize/v2 (go). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| qax-os/excelizegeneric | >=2.0.0 <=2.11.0 || >=1.1.0 <=1.4.1 | Not reported |
| github.com/xuri/excelizego | >=1.1.0,<=1.4.1 | Not reported |
| github.com/xuri/excelize/v2go | >=2.0.0,<2.11.1-0.20260910071107-696050fbf14e | 2.11.1-0.20260910071107-696050fbf14e |
Published upstream
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 7, 2026
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.0.0 to 2.11.0 in github.com/xuri/excelize/v2 and from 1.1.0 to 1.4.1 in github.com/xuri/excelize, ColumnNameToNumber accumulates a bijective base-26 value in int64 without detecting overflow, allowing an invalid long column name to wrap to zero with no error. ColumnNameToNumber accepts the overflowing name VGWQHXLSDVIKWV, after which checkSheetR0 and xlsxWorksheet.checkRow use the wrapped column value as an index. When a crafted worksheet uses an overflowing column name in a row normalized by checkSheetR0 or checkRow, the wrapped zero column becomes a negative slice index during worksheet normalization, allowing an attacker to panic and terminate the calling process. No fixed version is available as of this review.
Quoted source text, attributed separately from HOL analysis.