Skip to content
Threat Feed
medium advisory updated

Unbounded Decryption SpinCount Denial of Service in Excelize

An unbounded key-derivation loop in the Excelize library allows an attacker to trigger CPU exhaustion via a maliciously crafted EncryptionInfo stream in an OLE-formatted file.

CVE search metadata

CVE search record: CVE-2026-107219. Severity: high. CVSS: 7.5. KEV: no. Product: excelize (>= 2.3.1, < 2.11.1-0.20260906004932-2badfcd5841d), excelize (>= 2.8.1, < 2.11.1-0.20261003002531-6258dcebc4e2), excelize (< 2.11.1-0.20260930021559-01a9ff32fb3c), excelize (>= 2.9.0, < 2.11.1-0.20260929015830-8ffeb07ec9a3), excelize (>= 2.3.1, < 2.11.1-0.20260915055537-22f76f9acb94), excelize (>= 2.3.1, < 2.11.1-0.20260912113515-5f636f9dcde5), excelize (>= 2.8.1, < 2.11.1-0.20260911060113-ea12859e43c6). Brief: Unbounded Decryption SpinCount Denial of Service in Excelize. Brief link: https://feed.craftedsignal.io/briefs/2026-10-excelize-dos/

What's new

  • 1. added coverage for excelize (>= 2.8.1, < 2.11.1-0.20260911060113-ea12859e43c6) Oct 8, 19:27 via ghsa
  • 2. added coverage for excelize (>= 2.3.1, < 2.11.1-0.20260912113515-5f636f9dcde5) Oct 8, 19:27 via ghsa
  • 3. added coverage for excelize (>= 2.3.1, < 2.11.1-0.20260915055537-22f76f9acb94) Oct 8, 19:27 via ghsa
  • 4. added coverage for excelize (>= 2.9.0, < 2.11.1-0.20260929015830-8ffeb07ec9a3) Oct 8, 19:27 via ghsa
  • 5. added coverage for excelize (< 2.11.1-0.20260930021559-01a9ff32fb3c) Oct 8, 19:26 via ghsa

The Excelize Go library (versions 2.3.1 through 2.11.0) contains a denial-of-service vulnerability triggered by the lack of bounds checking on the spinCount parameter during the agile decryption process. The library branches into the decryption routine based solely on the first eight bytes of a file (the OLE magic number), regardless of whether the file is legitimately encrypted or if the application supports encrypted workbooks.

The crypt.go module reads the spinCount value directly from the XML-unmarshaled EncryptionInfo stream without validation. An attacker can supply an arbitrarily large integer for spinCount, forcing the convertPasswdToKey function to perform a CPU-intensive key derivation loop for that many iterations. Because the operation does not accept a context.Context, it cannot be canceled by the caller, leading to prolonged CPU exhaustion that persists even after the calling application hits request timeouts. The vulnerability impacts any application using Excelize to parse untrusted OLE files.

Attack Chain

  1. Attacker crafts a malicious file, ensuring the first eight bytes match the OLE magic number to trigger the Excelize file-parsing routine.
  2. Attacker embeds a crafted EncryptionInfo stream within the file structure.
  3. Attacker sets the spinCount element in the XML stream to a high integer value (e.g., 100,000,000+).
  4. Victim application attempts to open the file using excelize.OpenFile.
  5. openReaderAt detects the OLE header and invokes agileDecrypt without verifying if the file requires decryption.
  6. agileDecrypt calls convertPasswdToKey, which initiates a long-running loop based on the attacker-controlled spinCount.
  7. The process consumes CPU resources linearly, causing high load and blocking the goroutine from returning, resulting in an effective Denial of Service for the application instance.

Impact

Successful exploitation results in a Denial of Service (DoS) for the application processing the file. Since the operations run independently of the caller context, resources remain locked until the loop finishes, potentially exhausting server CPU resources if multiple malicious files are submitted concurrently. This vulnerability primarily affects applications that process user-uploaded Excel files (e.g., web-based document converters, data analysis tools, or enterprise reporting portals).

Recommendation

Prioritized actions for development and security teams:

  • Upgrade the Excelize library to version 2.11.1-0.20260906004932-2badfcd5841d or later to implement proper bounds checking on the spinCount value.
  • Implement file-size or process-time limits at the application layer for all file parsing routines that utilize Excelize, as the library does not natively support context-based cancellation.
  • Scan incoming files for the OLE magic number (first 8 bytes) and validate the EncryptionInfo stream structure before passing the file to the excelize library in high-exposure environments.

Immediate actions

Upgrade Excelize to version 2.11.1-0.20260906004932-2badfcd5841d

IT Operations 48h

Mitigations

Implement request timeout and CPU monitoring for any application service using Excelize to parse user files.

short_term Application Security

CVE-2026-107219