{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/excelize--2.9.0--2.11.1-0.20260929015830-8ffeb07ec9a3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:xuri:excelize:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-107219"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["excelize (\u003e= 2.3.1, \u003c 2.11.1-0.20260906004932-2badfcd5841d)","excelize (\u003e= 2.8.1, \u003c 2.11.1-0.20261003002531-6258dcebc4e2)","excelize (\u003c 2.11.1-0.20260930021559-01a9ff32fb3c)","excelize (\u003e= 2.9.0, \u003c 2.11.1-0.20260929015830-8ffeb07ec9a3)","excelize (\u003e= 2.3.1, \u003c 2.11.1-0.20260915055537-22f76f9acb94)","excelize (\u003e= 2.3.1, \u003c 2.11.1-0.20260912113515-5f636f9dcde5)","excelize (\u003e= 2.8.1, \u003c 2.11.1-0.20260911060113-ea12859e43c6)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","vulnerability","Go","excelize","golang"],"_cs_type":"advisory","_cs_vendors":["xuri"],"content_html":"\u003cp\u003eThe Excelize Go library (versions 2.3.1 through 2.11.0) contains a denial-of-service vulnerability triggered by the lack of bounds checking on the \u003ccode\u003espinCount\u003c/code\u003e parameter during the agile decryption process. The library branches into the decryption routine based solely on the first eight bytes of a file (the OLE magic number), regardless of whether the file is legitimately encrypted or if the application supports encrypted workbooks.\u003c/p\u003e\n\u003cp\u003eThe \u003ccode\u003ecrypt.go\u003c/code\u003e module reads the \u003ccode\u003espinCount\u003c/code\u003e value directly from the XML-unmarshaled \u003ccode\u003eEncryptionInfo\u003c/code\u003e stream without validation. An attacker can supply an arbitrarily large integer for \u003ccode\u003espinCount\u003c/code\u003e, forcing the \u003ccode\u003econvertPasswdToKey\u003c/code\u003e function to perform a CPU-intensive key derivation loop for that many iterations. Because the operation does not accept a \u003ccode\u003econtext.Context\u003c/code\u003e, it cannot be canceled by the caller, leading to prolonged CPU exhaustion that persists even after the calling application hits request timeouts. The vulnerability impacts any application using Excelize to parse untrusted OLE files.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker crafts a malicious file, ensuring the first eight bytes match the OLE magic number to trigger the Excelize file-parsing routine.\u003c/li\u003e\n\u003cli\u003eAttacker embeds a crafted \u003ccode\u003eEncryptionInfo\u003c/code\u003e stream within the file structure.\u003c/li\u003e\n\u003cli\u003eAttacker sets the \u003ccode\u003espinCount\u003c/code\u003e element in the XML stream to a high integer value (e.g., 100,000,000+).\u003c/li\u003e\n\u003cli\u003eVictim application attempts to open the file using \u003ccode\u003eexcelize.OpenFile\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eopenReaderAt\u003c/code\u003e detects the OLE header and invokes \u003ccode\u003eagileDecrypt\u003c/code\u003e without verifying if the file requires decryption.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eagileDecrypt\u003c/code\u003e calls \u003ccode\u003econvertPasswdToKey\u003c/code\u003e, which initiates a long-running loop based on the attacker-controlled \u003ccode\u003espinCount\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe process consumes CPU resources linearly, causing high load and blocking the goroutine from returning, resulting in an effective Denial of Service for the application instance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a Denial of Service (DoS) for the application processing the file. Since the operations run independently of the caller context, resources remain locked until the loop finishes, potentially exhausting server CPU resources if multiple malicious files are submitted concurrently. This vulnerability primarily affects applications that process user-uploaded Excel files (e.g., web-based document converters, data analysis tools, or enterprise reporting portals).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Excelize library to version 2.11.1-0.20260906004932-2badfcd5841d or later to implement proper bounds checking on the \u003ccode\u003espinCount\u003c/code\u003e value.\u003c/li\u003e\n\u003cli\u003eImplement file-size or process-time limits at the application layer for all file parsing routines that utilize Excelize, as the library does not natively support context-based cancellation.\u003c/li\u003e\n\u003cli\u003eScan incoming files for the OLE magic number (first 8 bytes) and validate the \u003ccode\u003eEncryptionInfo\u003c/code\u003e stream structure before passing the file to the \u003ccode\u003eexcelize\u003c/code\u003e library in high-exposure environments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:27:38Z","date_published":"2026-10-07T22:53:15Z","id":"https://feed.craftedsignal.io/briefs/2026-10-excelize-dos/","summary":"An unbounded key-derivation loop in the Excelize library allows an attacker to trigger CPU exhaustion via a maliciously crafted EncryptionInfo stream in an OLE-formatted file.","title":"Unbounded Decryption SpinCount Denial of Service in Excelize","url":"https://feed.craftedsignal.io/briefs/2026-10-excelize-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Excelize (\u003e= 2.9.0, \u003c 2.11.1-0.20260929015830-8ffeb07ec9a3)","version":"https://jsonfeed.org/version/1.1"}