Executive brief
Excelize is a Go library used to read, write, and manipulate XLSX spreadsheet files. The streaming row reader (GetRows function) fails to validate row numbers the same way the standard parser does, allowing an attacker to provide a malicious XLSX file that causes the application to allocate massive amounts of memory based on an attacker-supplied row index, even if the file is tiny. This can exhaust available memory and CPU on the host system, causing a denial of service.
Technical details
The vulnerability is a resource-consumption bypass in Excelize's streaming worksheet reader. The checked parser path (used by standard parsing) enforces row-number limits via checkRowNum() before allocating rows. However, the streaming path used by Rows() and GetRows() directly decodes XML without applying this validation. When parsing a row element with an out-of-bounds r attribute (e.g., r="2000000"), GetRows materializes empty row slices up to that row index without validation. A cell element without an r coordinate attribute can still contain data, allowing the attack to work without triggering cell-level validation. The attack requires only the ability to provide an XLSX file to an application that calls GetRows. A proof-of-concept demonstrates that row r="2000000" allocates approximately 46 MB for a tiny file. Larger row numbers scale the allocation further. The fix was released in version 2.11.0 and involves applying row-bound validation in the streaming reader immediately after parsing row r attributes.
Affected products
- xuri excelize <= 1.4.0
- xuri excelize/v2 < 2.11.0
Timeline
- 2026-09-10: disclosed: Vulnerability advisory published
- 2026-09-10: patched: Fixed in v2.11.0