{"id":"GO-2026-6453","summary":"Unbounded memory allocation via streaming row reader in github.com/xuri/excelize","details":"In github.com/xuri/excelize/v2, the streaming worksheet reader used by Rows and GetRows does not enforce the maximum row limit (TotalRows) on row \"r\" attributes. A crafted spreadsheet with an out-of-bounds row index causes GetRows to allocate empty row slices up to the specified row number, leading to excessive memory consumption and denial of service.","aliases":["CVE-2026-59161","GHSA-q5j5-6p94-4gwc"],"modified":"2026-09-17T17:30:11.249324252Z","published":"2026-09-16T18:00:43Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6453"},"references":[{"type":"ADVISORY","url":"https://github.com/qax-os/excelize/security/advisories/GHSA-q5j5-6p94-4gwc"},{"type":"FIX","url":"https://github.com/qax-os/excelize/commit/93f0b3caed37f21ef5079e3259c6c21dcfe68453"},{"type":"FIX","url":"https://github.com/qax-os/excelize/pull/2331"},{"type":"WEB","url":"https://github.com/qax-os/excelize/releases/tag/v2.11.0"}],"affected":[{"package":{"name":"github.com/xuri/excelize/v2","ecosystem":"Go","purl":"pkg:golang/github.com/xuri/excelize/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.11.0"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/xuri/excelize/v2","symbols":["File.GetRows","Rows.Close","Rows.Next"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6453.json"}}],"schema_version":"1.9.0"}