Answer in brief
CVE-2026-107224 records a Medium severity (CVSS 6.5) vulnerability in Excelize: A Zip64 uncompressed-size of 2^63 panics OpenFile/OpenReader. The current sources do not mark it as known exploited. The current feed maps qax-os/excelize (generic), github.com/xuri/excelize/v2 (go). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps qax-os/excelize (generic), github.com/xuri/excelize/v2 (go). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| qax-os/excelizegeneric | >=2.1.0 <=2.11.0 | Not reported |
| github.com/xuri/excelize/v2go | >=2.1.0,<2.11.1-0.20260805032953-db93f8d89de7 | 2.11.1-0.20260805032953-db93f8d89de7 |
Published upstream
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 7, 2026
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.1.0 to 2.11.0, a Zip64 uncompressed size with the high bit set is converted from uint64 to a negative int64 before signed size-limit checks and allocation. ReadZipReader obtains UncompressedSize64 through FileInfo.Size and passes the wrapped negative value to readFile. When a crafted Zip64 entry declares an uncompressed size from 2^63 through 2^64-1 and the workbook is opened, the negative size bypasses unzip limits and reaches make as a negative capacity, allowing an attacker to panic during workbook opening. No fixed version is available as of this review.
Quoted source text, attributed separately from HOL analysis.