Listen to this Post
The vulnerability resides in the `GetSlicers` function of the Excelize library, specifically within slicer.go. When processing worksheet parts, the code checks if `ws.ExtLst == nil` but fails to perform a necessary nil check on `ws.Drawing` before attempting to access its `RID` property. `Drawing` and `ExtLst` are independently optional child elements parsed from the worksheet XML structure. If an untrusted `.xlsx` file contains an `extLst` tag while omitting the drawing element, `ws.Drawing` remains nil. Consequently, calling `GetSlicers` triggers a runtime nil pointer dereference, causing an unhandled panic and leading to a denial of service (DoS) in applications consuming untrusted spreadsheet data.
DailyCVE Form:
Platform: Go / Excelize
Version: v2.11.0
Vulnerability : Nil Pointer Dereference
Severity: Critical
date: 2026-09-27
Prediction: 2026-10-15
What Undercode Say:
Bash Commands and Code
go version go1.27.0 windows/amd64 go build ./... go test -run TestGetSlicersNilDrawingPanic -v . go build -o repro.exe . ./repro.exe
// Vulnerable snippet from slicer.go
if ws.ExtLst == nil {
return slicers, err
}
target := f.getSheetRelationshipsTargetByID(sheet, ws.Drawing.RID) // Panics if ws.Drawing is nil
Exploit: (Educational Purposes!)
An attacker can craft a malicious `.xlsx` archive by modifying the internal `xl/worksheets/sheet1.xml` file. By inserting a bare `nil. When an application calls the public `File.GetSlicers()` API on this workbook, the library unconditionally attempts to dereference ws.Drawing.RID, resulting in a fatal process crash and denial of service.
Protection:
Upgrade to a patched version of the Excelize library where explicit nil checks are implemented for `ws.Drawing` before accessing its fields. Alternatively, wrap spreadsheet processing logic in robust recovery blocks (recover()) to handle unexpected panics gracefully when parsing untrusted files.
Impact:
Successful exploitation allows unauthenticated attackers to crash applications parsing untrusted Excel files via a single crafted XML tag, resulting in a complete denial of service (DoS) affecting systems relying on the vulnerable library.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

