{"id":"GHSA-wp2g-vpjj-g53r","summary":"Excelize ANCHORARRAY: mutually-referencing array formulas recurse unboundedly via re-entrant CalcCellValue, causing a fatal stack overflow","details":"### Summary\n\n`ANCHORARRAY` (calc.go:15137 on current master) evaluates each cell of the referenced spill range by calling the **exported** `CalcCellValue`, which unconditionally constructs a fresh `calcContext` — fresh entry marker, fresh iterations map, full `MaxCalcIterations` budget (calc.go:896-900). The circular-reference control only exists **within one context**: the entry-exclusion marker and per-ref iteration budget are fields of that single context, and completion-based caching (`formulaArgCache`/`calcRawCache`) only ever stores results of evaluations that *finish*.\n\nDuring a pure cycle no nested evaluation ever finishes, so nothing is ever cached to break the recursion, and each hop re-arms the entire budget. Two ordinary, Excel-legal constructs in an attacker-supplied workbook are enough:\n\n- `A1` (dynamic array formula, ref `A1:A1`): `_xlfn.ANCHORARRAY($B$1)`\n- `B1` (dynamic array formula, ref `B1:B1`): `_xlfn.ANCHORARRAY($A$1)`\n\n→ `CalcCellValue → calcCellValue → evalInfixExp → parseReference → cellResolver → … → ANCHORARRAY → CalcCellValue → …` forever, ending in a **fatal, unrecoverable** Go runtime error: `runtime: goroutine stack exceeds …-byte limit / fatal error: stack overflow`. Go stack overflows cannot be recovered — the whole process aborts.\n\n### Details\n\n- The terminating edge the iterations gate is supposed to provide does not exist across contexts: there is no in-flight tracking shared between nested `CalcCellValue` calls.\n- Both formulas are ordinary Excel-legal constructs; no exotic XML is required.\n- Excelize's own APIs reach formula evaluation on untrusted cells implicitly (e.g. `pivotTable.go:538`, `picture.go:985/1141`, `col.go:892`), so a service that merely adds a pivot table or a picture over such a workbook dies.\n- No option value prevents it: `MaxCalcIterations` is irrelevant because every hop gets a fresh budget.\n- Measured: a 64 MB stack budget is exhausted in ~0.09 s; the ~1 GB default in ~1–2 s.\n\n### PoC\n\nA standalone program (public API only) was provided to the maintainer by email (`4-anchorarray-recursion`): `NewFile` + `SetCellFormula` with `FormulaOpts{Type: array, Ref: A1:A1 / B1:B1}`, then `CalcCellValue(\"Sheet1\",\"A1\")`. On master `ecd99d761fe0` (2026-09-08) the process aborts with `fatal error: stack overflow`; with the proposed patch the cycle terminates normally (`CYCLE_TERMINATED`) and existing calc tests pass.\n\n### Impact\n\nAn attacker ships a workbook containing the two formulas; any service that evaluates a formula over those cells — directly via `CalcCellValue`, or implicitly via `AddPivotTable` / `AddPicture` / auto-fit — aborts. Remote, unauthenticated, process-fatal, no configuration prevents it.\n\n### Proposed fix\n\nEvaluate spill-range cells through the **current** calculation context — `fn.f.cellResolver(fn.ctx, …)` instead of the exported `CalcCellValue` — so the entry check and iterations gate of the running calculation apply. `cellResolver` returns the typed value directly (dropping a string round-trip); an `ArgEmpty → \"\"` shim preserves the existing `ToNumber` behavior for empty spill cells, and a fresh-context fallback covers the legacy nil-ctx test paths. A complete patch has been provided to the maintainer.","aliases":["CVE-2026-107216"],"modified":"2026-10-08T16:45:19.289323668Z","published":"2026-10-08T16:31:21Z","database_specific":{"github_reviewed_at":"2026-10-08T16:31:21Z","nvd_published_at":"2026-10-07T18:17:19Z","cwe_ids":["CWE-674"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/qax-os/excelize/security/advisories/GHSA-wp2g-vpjj-g53r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107216"},{"type":"WEB","url":"https://github.com/qax-os/excelize/commit/ea12859e43c64d498ecf839263c5f917391f3316"},{"type":"PACKAGE","url":"https://github.com/qax-os/excelize"}],"affected":[{"package":{"name":"github.com/xuri/excelize/v2","ecosystem":"Go","purl":"pkg:golang/github.com/xuri/excelize/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.8.1"},{"fixed":"2.11.1-0.20260911060113-ea12859e43c6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-wp2g-vpjj-g53r/GHSA-wp2g-vpjj-g53r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}