CVE-2026-59162

Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, Excelize parses shared-string cell values with strconv.Atoi and checks only the upper bound before indexing the shared string slice, allowing an XLSX file containing a shared-string cell with -1 to trigger sharedStrings[-1] and panic when read through GetCellValue or GetRows. This issue is fixed in version 2.11.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:excelize:excelize:*:*:*:*:*:go:*:*

History

No history.

Information

Published : 2026-07-10 17:17

Updated : 2026-07-16 13:44


NVD link : CVE-2026-59162

Mitre link : CVE-2026-59162

CVE.ORG link : CVE-2026-59162


JSON object : View

Products Affected

excelize

  • excelize
CWE
CWE-248

Uncaught Exception

CWE-755

Improper Handling of Exceptional Conditions