THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-q5j5-6p94-4gwc (high) — Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation

[GHSA] GHSA-q5j5-6p94-4gwc (high) — Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation

highgithub_advisoriesPublished 2026-09-10

GHSA-q5j5-6p94-4gwc Severity: high CVE: CVE-2026-59161

Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation

# Streaming GetRows row-bound bypass causes attacker-controlled allocation

## Summary

Excelize's prior row-bound fix for GHSA-h69g / CVE-2026-54063 protects the checked worksheet parser, but the streaming worksheet reader used by `Rows` and `GetRows` does no

Indicators of compromise

Original source: https://github.com/advisories/GHSA-q5j5-6p94-4gwc