Vulnerability GO-2026-6452
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
11 days ago
September 16, 2026 at 06:00 PM UTC
Panic via negative shared-string index in github.com/xuri/excelize
v2.0.0 - v2.10.1
v2.0.0 - v2.10.1
Summary
Panic via negative shared-string index in github.com/xuri/excelize
Details
In github.com/xuri/excelize/v2, parsing a spreadsheet cell with a negative shared-string index causes a runtime panic. The shared-string lookup in xlsxC.getValueFrom checks only the upper bound of the parsed index against the shared-string slice length, causing negative indices (such as -1) to bypass validation and trigger an out-of-bounds slice access when reading cells via APIs such as GetCellValue or GetRows.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
11 days ago
Unbounded memory allocation via streaming row reader in github.com/xuri/excelize
v2.0.0 - v2.10.1 GO-2026-6453
v2.0.0 - v2.10.1 GO-2026-6453
High Risk
17 days ago
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
v2.0.0 - v2.10.1 GHSA-q5j5-6p94-4gwc
v2.0.0 - v2.10.1 GHSA-q5j5-6p94-4gwc
Medium Risk
17 days ago
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
v2.0.0 - v2.10.1 GHSA-fx5j-qcqg-grpf
v2.0.0 - v2.10.1 GHSA-fx5j-qcqg-grpf
Unknown
2 months ago
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS) in github.com/xuri/excelize
v2.0.0 - v2.10.1 GO-2026-5960
v2.0.0 - v2.10.1 GO-2026-5960
High Risk
2 months ago
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
v2.0.0 - v2.10.1 GHSA-h69g-9hx6-f3v4
v2.0.0 - v2.10.1 GHSA-h69g-9hx6-f3v4
Impacted packages
Timeline
Published
11 days ago
September 16, 2026 at 06:00 PM UTC
Last Modified
3 days ago
September 24, 2026 at 08:30 PM UTC