<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Excelize (&gt;= 2.3.1, &lt; 2.11.1-0.20260912113515-5f636f9dcde5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/excelize--2.3.1--2.11.1-0.20260912113515-5f636f9dcde5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:53:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/excelize--2.3.1--2.11.1-0.20260912113515-5f636f9dcde5/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unbounded Decryption SpinCount Denial of Service in Excelize</title><link>https://feed.craftedsignal.io/briefs/2026-10-excelize-dos/</link><pubDate>Wed, 07 Oct 2026 22:53:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-excelize-dos/</guid><description>An unbounded key-derivation loop in the Excelize library allows an attacker to trigger CPU exhaustion via a maliciously crafted EncryptionInfo stream in an OLE-formatted file.</description><content:encoded><![CDATA[<p>The Excelize Go library (versions 2.3.1 through 2.11.0) contains a denial-of-service vulnerability triggered by the lack of bounds checking on the <code>spinCount</code> parameter during the agile decryption process. The library branches into the decryption routine based solely on the first eight bytes of a file (the OLE magic number), regardless of whether the file is legitimately encrypted or if the application supports encrypted workbooks.</p>
<p>The <code>crypt.go</code> module reads the <code>spinCount</code> value directly from the XML-unmarshaled <code>EncryptionInfo</code> stream without validation. An attacker can supply an arbitrarily large integer for <code>spinCount</code>, forcing the <code>convertPasswdToKey</code> function to perform a CPU-intensive key derivation loop for that many iterations. Because the operation does not accept a <code>context.Context</code>, it cannot be canceled by the caller, leading to prolonged CPU exhaustion that persists even after the calling application hits request timeouts. The vulnerability impacts any application using Excelize to parse untrusted OLE files.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker crafts a malicious file, ensuring the first eight bytes match the OLE magic number to trigger the Excelize file-parsing routine.</li>
<li>Attacker embeds a crafted <code>EncryptionInfo</code> stream within the file structure.</li>
<li>Attacker sets the <code>spinCount</code> element in the XML stream to a high integer value (e.g., 100,000,000+).</li>
<li>Victim application attempts to open the file using <code>excelize.OpenFile</code>.</li>
<li><code>openReaderAt</code> detects the OLE header and invokes <code>agileDecrypt</code> without verifying if the file requires decryption.</li>
<li><code>agileDecrypt</code> calls <code>convertPasswdToKey</code>, which initiates a long-running loop based on the attacker-controlled <code>spinCount</code>.</li>
<li>The process consumes CPU resources linearly, causing high load and blocking the goroutine from returning, resulting in an effective Denial of Service for the application instance.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a Denial of Service (DoS) for the application processing the file. Since the operations run independently of the caller context, resources remain locked until the loop finishes, potentially exhausting server CPU resources if multiple malicious files are submitted concurrently. This vulnerability primarily affects applications that process user-uploaded Excel files (e.g., web-based document converters, data analysis tools, or enterprise reporting portals).</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for development and security teams:</p>
<ul>
<li>Upgrade the Excelize library to version 2.11.1-0.20260906004932-2badfcd5841d or later to implement proper bounds checking on the <code>spinCount</code> value.</li>
<li>Implement file-size or process-time limits at the application layer for all file parsing routines that utilize Excelize, as the library does not natively support context-based cancellation.</li>
<li>Scan incoming files for the OLE magic number (first 8 bytes) and validate the <code>EncryptionInfo</code> stream structure before passing the file to the <code>excelize</code> library in high-exposure environments.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category><category>Go</category><category>excelize</category><category>golang</category></item></channel></rss>