Vulnerability GO-2026-6453
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
11 days ago
September 16, 2026 at 06:00 PM UTC
Unbounded memory allocation via streaming row reader in github.com/xuri/excelize
v2.0.0 - v2.10.1
v2.0.0 - v2.10.1
Summary
Unbounded memory allocation via streaming row reader in github.com/xuri/excelize
Details
In github.com/xuri/excelize/v2, the streaming worksheet reader used by Rows and GetRows does not enforce the maximum row limit (TotalRows) on row "r" attributes. A crafted spreadsheet with an out-of-bounds row index causes GetRows to allocate empty row slices up to the specified row number, leading to excessive memory consumption and denial of service.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
11 days ago
Panic via negative shared-string index in github.com/xuri/excelize
v2.0.0 - v2.10.1 GO-2026-6452
v2.0.0 - v2.10.1 GO-2026-6452
High Risk
17 days ago
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
v2.0.0 - v2.10.1 GHSA-q5j5-6p94-4gwc
v2.0.0 - v2.10.1 GHSA-q5j5-6p94-4gwc
Medium Risk
17 days ago
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows
v2.0.0 - v2.10.1 GHSA-fx5j-qcqg-grpf
v2.0.0 - v2.10.1 GHSA-fx5j-qcqg-grpf
Unknown
2 months ago
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS) in github.com/xuri/excelize
v2.0.0 - v2.10.1 GO-2026-5960
v2.0.0 - v2.10.1 GO-2026-5960
High Risk
2 months ago
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)
v2.0.0 - v2.10.1 GHSA-h69g-9hx6-f3v4
v2.0.0 - v2.10.1 GHSA-h69g-9hx6-f3v4
Impacted packages
Timeline
Published
11 days ago
September 16, 2026 at 06:00 PM UTC
Last Modified
10 days ago
September 17, 2026 at 05:30 PM UTC