← Zurück zur Schwachstellenliste

CVE-2026-50648

Beschreibung
CVE-ID
CVE-2026-50648
Paket
System.Security.Cryptography.Xml
Schweregrad von CVE
High
EPPlus Wirkung
Low
Betroffene EPPlus-Versionen

8.0.1 – 8.6.2

Status

fix-available — Eine Lösung ist verfügbar. Siehe Hinweis für Details.

Beratung

Microsoft has released a security fix for a denial of service vulnerability (CVE-2026-50648) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. EPPlus uses this package to create and validate digital signatures for workbooks. The risk for EPPlus users is considered very low, as EPPlus does not expose any way for an external attacker to control the input passed to the affected library. The package is only used to process workbooks that the EPPlus user has either created themselves or chosen to open as trusted.

Update to EPPlus 8.6.3 to resolve this issue.

Informationen zur Paketkorrektur

Diese Information bezieht sich auf das Upstream-Paket (System.Security.Cryptography.Xml), nicht auf EPPlus. Siehe die obige Empfehlung für EPPlus-spezifische Leitlinien.

Target framework Paketversion Fix State In der Version behoben
net8.0 9.0.15 fixed 9.0.18
net8.0 8.0.3 fixed 8.0.4
net8.0 8.0.2 fixed 8.0.4
net9.0 9.0.3 fixed 9.0.18
net9.0 9.0.15 fixed 9.0.18
net10.0 10.0.0 fixed 10.0.10
net10.0 10.0.7 fixed 10.0.10
net10.0 10.0.6 fixed 10.0.10
net462 9.0.15 fixed 9.0.18
net462 8.0.2 fixed 8.0.4
net462 8.0.3 fixed 8.0.4
netstandard2.0 8.0.2 fixed 8.0.4
netstandard2.0 9.0.15 fixed 9.0.18
netstandard2.0 8.0.3 fixed 8.0.4
netstandard2.1 9.0.15 fixed 9.0.18
netstandard2.1 8.0.3 fixed 8.0.4
netstandard2.1 8.0.2 fixed 8.0.4
Zeitstrahl
Zuerst entdeckt
2026-07-22
Zuletzt aktualisiert
2026-07-24
← Zurück zur Schwachstellenliste