THREAT OPS › Threat News › [GHSA] GHSA-q5j5-6p94-4gwc (high) — Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
[GHSA] GHSA-q5j5-6p94-4gwc (high) — Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
GHSA-q5j5-6p94-4gwc Severity: high CVE: CVE-2026-59161
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation
# Streaming GetRows row-bound bypass causes attacker-controlled allocation
## Summary
Excelize's prior row-bound fix for GHSA-h69g / CVE-2026-54063 protects the checked worksheet parser, but the streaming worksheet reader used by `Rows` and `GetRows` does no
Indicators of compromise
- 1213a8bd7c5ab360554603ac5c995ccaf6eb4314sha1
- 5ad5ab3af0054c55bdce09f1530085600e9f2e45sha1
- CVE-2026-59161cve
- CVE-2026-54063cve
- http://schemas.openxmlformats.org/spreadsheetml/2006/mainurl
Original source: https://github.com/advisories/GHSA-q5j5-6p94-4gwc