Excelize, Unrecoverable Decryption Panic, CVE-2026-107214 (critical) -DC-Oct2026-2918

Listen to this Post

The CVE-2026-107214 vulnerability affects the Excelize Go package.

It targets the file decryption handling for OLE compound documents.

Applications using OpenFile, OpenReader, or OpenBytes are impacted.

Untrusted spreadsheets containing valid OLE headers trigger decryption.

Files route through openReaderAt down to the Decrypt function.

The core flaw involves insufficient structural parameter verification.

Version dispatch checks only that EncryptionInfo length is at least 4.
It fails to perform exhaustive validation on internal stream headers.

Attacker-controlled EncryptionInfo buffers pass directly to decrypters.

StandardDecrypt and agileDecrypt receive unvalidated input buffers.

Multiple unvalidated assumptions regarding slice boundaries are made.

Header offsets, key sizes, and block sizes lack proper checks.

Malformed yet version-valid content triggers unrecovered runtimes.

Instead of returning structured errors, execution faults occur.

Calling processes are abruptly terminated via runtime panics.

Standard encryption paths trigger out-of-bounds slice indexing.

Index errors occur when length indicators fall into restricted ranges.

Key size specifications mismatch allocated memory capacities.

Agile encryption routines fail when key encryptors are absent.
Missing XML elements cause index out of range exceptions.

Decoded salt lengths mismatch required AES block sizes.

Cryptographic initializers fault during block decrypter creation.

Error-mapping logic in excelize.go is completely bypassed.

Normal error handling paths for ErrWorkbookFileFormat are missed.

Remote unauthenticated attackers can exploit this vulnerability easily.

Services processing uploaded files face instant denial of service.
Files between 100 bytes and 3 KB are sufficient to crash processes.
No password is required since panics occur during parsing.

Comprehensive defensive recovery boundaries are urgently needed.

DailyCVE Form:

Platform: Excelize library
Version: 2.3.1-2.11.0
Vulnerability: Decryption panic
Severity: Critical risk
date: 2026-10-07

Prediction: 2026-10-14

What Undercode Say

Analysis of the decryption mechanism reveals multiple structural validation gaps in `crypt.go` where attacker-controlled headers trigger unrecovered panics instead of returning ErrWorkbookFileFormat.

Clone and inspect excelize repository at vulnerable commit
git clone https://github.com/qax-os/excelize.git
cd excelize
git checkout ecd99d761fe0
// Example vulnerable decryption entry point snippet
func (f File) Decrypt(password string) error {
return f.decrypt(password)
}

Exploit: (Educational Purposes!)

Constructing a malformed OLE compound file container with a version-valid `EncryptionInfo` stream where `len(EncryptionInfo)` is between 4 and 11 bytes causes an out-of-bounds slice access (slice bounds [:12]) at crypt.go:238. Similarly, supplying an attacker-controlled `headerSize` or setting `header.KeySize = 0xFFFFFFFF` forces oversized memory allocations and panic conditions, crashing any service parsing the spreadsheet without authentication.

Protection:

Implement a `recover()` boundary within the `Decrypt` function to catch any runtime panics and map them safely to ErrWorkbookFileFormat, restoring the documented error-routing contract. Additionally, apply strict per-site length validations on EncryptionInfo, EncryptedPackage, header sizes, and key sizes as defense-in-depth measures before processing untrusted inputs.

Impact:

Any automated service, web application, or backend pipeline invoking OpenFile, OpenReader, or `OpenBytes` on untrusted spreadsheet uploads can be remotely and unauthentically crashed via Denial of Service using small malformed files ranging from 100 bytes to 3 KB.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top