<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T21:36:27.381834+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335729</id>
    <title>EUVD-2026-335729</title>
    <updated>2026-10-06T21:36:27.431891+00:00</updated>
    <content>EUVD-2026-335729</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335729"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54063</id>
    <title>fkie_cve-2026-54063</title>
    <updated>2026-10-06T21:36:27.431928+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet() function in github.com/xuri/excelize/v2 uses an attacker-controlled &lt;row r="N"&gt; XML attribute value directly as the length argument to make([]xlsxRow, row) without validating it against the Excel row limit (TotalRows = 1,048,576). A specially crafted XLSX file can trigger two denial-of-service variants: (A) an out-of-memory process kill when r=2147483647 forces a ~16 GB allocation attempt, and (B) a runtime panic via out-of-bounds slice indexing when r=-1. Any service that opens attacker-supplied XLSX files and calls GetCellValue is affected. No authentication is required. This issue is fixed in version 2.11.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54063"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h69g-9hx6-f3v4</id>
    <title>GHSA-h69g-9hx6-f3v4 — Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)</title>
    <updated>2026-10-06T21:36:27.431965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/xuri/excelize/v2</p>
<p>## Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)</p>
<p>### Summary
The `checkSheet()` function in `github.com/xuri/excelize/v2` uses an attacker-controlled `&lt;row r="N"&gt;` XML attribute value directly as the length argument to `make([]xlsxRow, row)` without validating it against the Excel row limit (`TotalRows = 1,048,576`). A specially crafted XLSX file can trigger two denial-of-service variants: (A) an out-of-memory process kill when `r=2147483647` forces a ~16 GB allocation attempt, and (B) a runtime panic via out-of-bounds slice indexing when `r=-1`. Any service that opens attacker-supplied XLSX files and calls `GetCellValue` is affected. No authentication is required.</p>
<p>### Details
The vulnerable code path is triggered by calling `GetCellValue` (or any API that internally invokes `workSheetReader`) on an XLSX file containing a crafted worksheet row element.</p>
<p>**Data flow (source → sink):**</p>
<p>1. `excelize.go:186-193` — `OpenReader` reads attacker-controlled spreadsheet bytes.
2. `excelize.go:216-223` — ZIP reader is created and passed to `ReadZipReader`.
3. `lib.go:43-77` — ZIP entries are read into `fileList`; worksheet XML is stored by part name.
4. `excelize.go:228-229` — XML bytes are stored in `f.Pkg`.
5. `cell.go:71-79` — Public `GetCellValue` enters the worksheet value-read path.
6. `cell.go:1492-1494` — `getCellStringFunc` calls `workSheetReader`.
7. `excelize.go:313-324` — Worksheet XML is decoded into `xlsxWorksheet`.
8. `xmlWorksheet.go:3…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h69g-9hx6-f3v4"/>
  </entry>
</feed>
