Excelize, Nil Pointer Dereference, CVE-2026-XXXX (Critical) -DC-Oct2026-2926

Listen to this Post

The vulnerability resides in the `GetSlicers` function of the Excelize library, specifically within slicer.go. When processing worksheet parts, the code checks if `ws.ExtLst == nil` but fails to perform a necessary nil check on `ws.Drawing` before attempting to access its `RID` property. `Drawing` and `ExtLst` are independently optional child elements parsed from the worksheet XML structure. If an untrusted `.xlsx` file contains an `extLst` tag while omitting the drawing element, `ws.Drawing` remains nil. Consequently, calling `GetSlicers` triggers a runtime nil pointer dereference, causing an unhandled panic and leading to a denial of service (DoS) in applications consuming untrusted spreadsheet data.

DailyCVE Form:

Platform: Go / Excelize
Version: v2.11.0
Vulnerability : Nil Pointer Dereference
Severity: Critical
date: 2026-09-27

Prediction: 2026-10-15

What Undercode Say:

Bash Commands and Code

go version go1.27.0 windows/amd64
go build ./...
go test -run TestGetSlicersNilDrawingPanic -v .
go build -o repro.exe .
./repro.exe
// Vulnerable snippet from slicer.go
if ws.ExtLst == nil {
return slicers, err
}
target := f.getSheetRelationshipsTargetByID(sheet, ws.Drawing.RID) // Panics if ws.Drawing is nil

Exploit: (Educational Purposes!)

An attacker can craft a malicious `.xlsx` archive by modifying the internal `xl/worksheets/sheet1.xml` file. By inserting a bare `` tag while ensuring no `drawing` element is present, the XML parser leaves `ws.Drawing` as nil. When an application calls the public `File.GetSlicers()` API on this workbook, the library unconditionally attempts to dereference ws.Drawing.RID, resulting in a fatal process crash and denial of service.

Protection:

Upgrade to a patched version of the Excelize library where explicit nil checks are implemented for `ws.Drawing` before accessing its fields. Alternatively, wrap spreadsheet processing logic in robust recovery blocks (recover()) to handle unexpected panics gracefully when parsing untrusted files.

Impact:

Successful exploitation allows unauthenticated attackers to crash applications parsing untrusted Excel files via a single crafted XML tag, resulting in a complete denial of service (DoS) affecting systems relying on the vulnerable library.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top