The maintainers of the Go spreadsheet library Excelize patched two security flaws in v2.11.0, including CVE-2026-59161, a denial-of-service issue in the streaming worksheet reader used by Rows and GetRows. In affected versions before 2.11.0, a crafted XLSX file could set a worksheet row r attribute above Excel's maximum of 1,048,576 and omit cell coordinates, causing GetRows to append empty rows up to an attacker-controlled index and consume excessive memory and CPU.
The same fix set also addressed a second bug that could trigger a panic when retrieving a cell value with an invalid shared string table index. The changes, merged through pull request #2331 and commit 93f0b3caed37f21ef5079e3259c6c21dcfe68453, added explicit row-limit validation, bounds checks, and structured error handling instead of panics, with updated unit tests confirming both protections. Organizations using Excelize to process untrusted spreadsheet files should upgrade to v2.11.0.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
GitHub Security Advisories newly received CVE-2026-59161, a denial-of-service flaw in Excelize's streaming worksheet reader that could allow attacker-controlled memory and CPU consumption. The issue affected versions prior to 2.11.0 and was noted as fixed in version 2.11.0.
Excelize version 2.11.0 was released, addressing three security issues: CVE-2026-54063, CVE-2026-59161, and CVE-2026-59162. The release also included breaking API changes, bug fixes, performance improvements, and raised the minimum supported Go version to 1.25.0.
A patch was merged into the qax-os Excelize master branch to fix two security issues: attacker-controlled memory allocation via worksheet row number overflow and a panic caused by invalid shared string table indexes. The fixes added row bounds validation, replaced panic behavior with structured errors, and were associated with Excelize v2.11.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.