Unbounded Decryption SpinCount Denial of Service in Excelize
An unbounded key-derivation loop in the Excelize library allows an attacker to trigger CPU exhaustion via a maliciously crafted EncryptionInfo stream in an OLE-formatted file.
CVE search metadata
CVE search record: CVE-2026-107219. Severity: high. CVSS: 7.5. KEV: no. Product: excelize (>= 2.3.1, < 2.11.1-0.20260906004932-2badfcd5841d), excelize (>= 2.8.1, < 2.11.1-0.20261003002531-6258dcebc4e2), excelize (< 2.11.1-0.20260930021559-01a9ff32fb3c), excelize (>= 2.9.0, < 2.11.1-0.20260929015830-8ffeb07ec9a3), excelize (>= 2.3.1, < 2.11.1-0.20260915055537-22f76f9acb94), excelize (>= 2.3.1, < 2.11.1-0.20260912113515-5f636f9dcde5), excelize (>= 2.8.1, < 2.11.1-0.20260911060113-ea12859e43c6). Brief: Unbounded Decryption SpinCount Denial of Service in Excelize. Brief link: https://feed.craftedsignal.io/briefs/2026-10-excelize-dos/
What's new
- 1. added coverage for excelize (>= 2.8.1, < 2.11.1-0.20260911060113-ea12859e43c6) Oct 8, 19:27 via ghsa
- 2. added coverage for excelize (>= 2.3.1, < 2.11.1-0.20260912113515-5f636f9dcde5) Oct 8, 19:27 via ghsa
- 3. added coverage for excelize (>= 2.3.1, < 2.11.1-0.20260915055537-22f76f9acb94) Oct 8, 19:27 via ghsa
- 4. added coverage for excelize (>= 2.9.0, < 2.11.1-0.20260929015830-8ffeb07ec9a3) Oct 8, 19:27 via ghsa
- 5. added coverage for excelize (< 2.11.1-0.20260930021559-01a9ff32fb3c) Oct 8, 19:26 via ghsa
The Excelize Go library (versions 2.3.1 through 2.11.0) contains a denial-of-service vulnerability triggered by the lack of bounds checking on the spinCount parameter during the agile decryption process. The library branches into the decryption routine based solely on the first eight bytes of a file (the OLE magic number), regardless of whether the file is legitimately encrypted or if the application supports encrypted workbooks.
The crypt.go module reads the spinCount value directly from the XML-unmarshaled EncryptionInfo stream without validation. An attacker can supply an arbitrarily large integer for spinCount, forcing the convertPasswdToKey function to perform a CPU-intensive key derivation loop for that many iterations. Because the operation does not accept a context.Context, it cannot be canceled by the caller, leading to prolonged CPU exhaustion that persists even after the calling application hits request timeouts. The vulnerability impacts any application using Excelize to parse untrusted OLE files.
Attack Chain
- Attacker crafts a malicious file, ensuring the first eight bytes match the OLE magic number to trigger the Excelize file-parsing routine.
- Attacker embeds a crafted
EncryptionInfostream within the file structure. - Attacker sets the
spinCountelement in the XML stream to a high integer value (e.g., 100,000,000+). - Victim application attempts to open the file using
excelize.OpenFile. openReaderAtdetects the OLE header and invokesagileDecryptwithout verifying if the file requires decryption.agileDecryptcallsconvertPasswdToKey, which initiates a long-running loop based on the attacker-controlledspinCount.- The process consumes CPU resources linearly, causing high load and blocking the goroutine from returning, resulting in an effective Denial of Service for the application instance.
Impact
Successful exploitation results in a Denial of Service (DoS) for the application processing the file. Since the operations run independently of the caller context, resources remain locked until the loop finishes, potentially exhausting server CPU resources if multiple malicious files are submitted concurrently. This vulnerability primarily affects applications that process user-uploaded Excel files (e.g., web-based document converters, data analysis tools, or enterprise reporting portals).
Recommendation
Prioritized actions for development and security teams:
- Upgrade the Excelize library to version 2.11.1-0.20260906004932-2badfcd5841d or later to implement proper bounds checking on the
spinCountvalue. - Implement file-size or process-time limits at the application layer for all file parsing routines that utilize Excelize, as the library does not natively support context-based cancellation.
- Scan incoming files for the OLE magic number (first 8 bytes) and validate the
EncryptionInfostream structure before passing the file to theexcelizelibrary in high-exposure environments.
Immediate actions
Upgrade Excelize to version 2.11.1-0.20260906004932-2badfcd5841d
Mitigations
Implement request timeout and CPU monitoring for any application service using Excelize to parse user files.
CVE-2026-107219