CVE-2026-107211EPSS p20.0%
CVE-2026-107211CVE-2026-107211
Description
Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.8.1 to 2.11.0, separately parsed pivot-table field indices are used to index the pivot-cache field-name slice without bounds checks. extractPivotTableFields uses getPivotCacheFieldsName output while processing GetPivotTables and trusts the dataField fld attribute as an index. When a crafted workbook supplies a pivot-field count mismatch or an out-of-range dataField fld value before GetPivotTables is called, the unchecked index causes a Go slice-bounds panic that escapes the library, allowing an attacker to crash the process or request worker. No fixed version is available as of this review.
Scoring
| EPSS | 0.29% probability of exploitation · percentile 20.0% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |