SCA: security update for github.com/xuri/excelize/v2 (GHSA-rxcj-4pj5-74gr)

medium Tenable Self-Hosted Container Security Plugin ID 473816

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. From 2.7.0 to
2.11.0, conditional-format extraction indexes required child slices or dereferences an optional colorScale
child without validating malformed rule structure. GetConditionalFormats reaches extractCondFmtCellIs and
also indexes ColorScale.Cfvo, DataBar.Cfvo, and DataBar.Color without complete structural checks. When a
crafted worksheet supplies a cellIs, dataBar, or colorScale rule missing expected children and the
application calls GetConditionalFormats, missing formula, color, value-object, or colorScale data reaches
an out-of-range index or nil dereference, allowing an attacker to panic and terminate an unprotected
process. No fixed version is available as of this review. (CVE-2026-107222)

Solution

Update the github.com/xuri/excelize/v2 library and its related packages to version 2.11.1-0.20260812075026-be7a16390fa6 or later.

See Also

https://github.com/advisories/GHSA-rxcj-4pj5-74gr

Plugin Details

Severity: Medium

ID: 473816

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/8/2026

Updated: 10/8/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-107222

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/7/2026

Vulnerability Publication Date: 10/7/2026

Reference Information

CVE: CVE-2026-107222