CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-107213: excelize >= 2.9.0, <= 2.11.0

Affected technology

excelize · >= 2.9.0, <= 2.11.0
qax-os

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source says when a crafted worksheet contains an extLst element without a drawing element and the application calls GetSlicers, the nil ws.Drawing pointer is dereferenced while resolving the drawing relationship, allowing an attacker to panic and terminate an unprotected process. Vendor/CNA’s CVSS 4.0 assessment (base score 8.7/10) rates confidentiality and integrity impact as none; availability impact as high.

Published

CWE
CWE-476
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-107213.html