Listen to this Post
CVE-2026-107215 affects the Excelize Go language library for reading and writing Microsoft Excel spreadsheets, specifically within the `extractPart` function located in crypt.go. When an application parses an encrypted workbook utilizing the Compound File Binary (CFB) format, `extractPart` allocates memory directly based on the raw `streamSize` field retrieved from an attacker-controlled CFB directory entry without prior validation or clamping. Because the underlying CFB parser delays sector chain validation until later inside File.Read, malicious inputs can declare extreme, malformed, or negative stream sizes freely. When a version-4 CFB specifies a `streamSize` of 0xFFFFFFFFFFFFFFFF, `entry.Size` becomes negative one, triggering a hard panic via `makeslice: len out of range` that escapes error handling within `Decrypt` and instantly crashes the host process. Alternatively, declaring a stream size up to 0xFFFFFFFF forces up to four gigabytes of zeroed memory allocation from a tiny twelve-kilobyte file, creating an amplification factor of approximately 350,000 times that easily leads to denial of service via out-of-memory termination when repeatedly requested against memory-constrained deployment environments.
DailyCVE Form:
Platform: Excelize
Version: 2.3.1 to 2.11.0
Vulnerability: Unbounded memory allocation
Severity: High
date: October 7, 2026
Prediction: Patch Available Now
(end of form)
What Undercode Say:
Analytics of the vulnerability indicate a critical design flaw in input parsing where untrusted OLE stream size parameters bypass preliminary boundary checks before slice allocation. Attackers leverage small file structures to induce massive memory requests or unrecovered panics, bypassing higher-level safety boundaries present in zip or KDF pathways. Proper defensive coding requires absolute bounds checking and negative size rejection prior to any slice creation.
Bash commands and codes:
go test -v ./... git clone https://github.com/xuri/excelize/v2.git go run main.go -oom
buf := make([]byte, entry.Size)
if entry.Size < 0 || entry.Size > maxSanePolicyCap {
return ErrWorkbookFileFormat
}
Exploit: (Educational Purposes!)
The exploit relies on constructing a valid-enough version-4 CFB file containing a specially crafted directory entry for `EncryptionInfo` where the stream size is explicitly set to 0xFFFFFFFFFFFFFFFF or 0xFFFFFFFF. When processed by excelize.OpenFile, the library attempts slice allocation using the unvalidated size field, resulting in an immediate process crash or severe memory exhaustion without requiring authentication or privileges.
Protection:
To protect against CVE-2026-107215, upgrade the Excelize library to a patched version where input sizes in `extractPart` are strictly bounded. Implement strict checks to reject negative sizes and enforce a sane policy cap such as one gigabyte before any memory allocation occurs, returning an error instead of panicking or consuming excessive memory resources.
Impact:
Successful exploitation allows remote and unauthenticated attackers to cause a complete denial of service via hard process panics or severe memory exhaustion through out-of-memory termination, leveraging massive amplification factors from tiny malicious payloads.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

