CVE-2026-47304
Beschreibung
- CVE-ID
- CVE-2026-47304
- Paket
- System.Security.Cryptography.Xml
- Schweregrad von CVE
- High
- EPPlus Wirkung
- Medium
Betroffene EPPlus-Versionen
8.0.1 – 8.6.2
Status
fix-available — Eine Lösung ist verfügbar. Siehe Hinweis für Details.
Beratung
Microsoft has released a security fix for a security feature bypass vulnerability (CVE-2026-47304) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. The vulnerability concerns improper verification of cryptographic signatures, which may allow an invalid signature to be accepted as valid. EPPlus uses this package to create and validate digital signatures for workbooks, including validating the signature of a workbook when it is read. Applications that rely on EPPlus to validate workbook signatures — for example, to determine the authenticity of a workbook of unknown or untrusted origin — should update promptly. As stated in our security profile, the host application remains responsible for deciding whether a file is trusted before passing it to EPPlus.
Update to EPPlus 8.6.3 to resolve this issue.
Informationen zur Paketkorrektur
Diese Information bezieht sich auf das Upstream-Paket (System.Security.Cryptography.Xml), nicht auf EPPlus. Siehe die obige Empfehlung für EPPlus-spezifische Leitlinien.
| Target framework | Paketversion | Fix State | In der Version behoben |
|---|---|---|---|
| net8.0 | 9.0.15 | fixed | 9.0.18 |
| net8.0 | 8.0.3 | fixed | 8.0.4 |
| net8.0 | 8.0.2 | fixed | 8.0.4 |
| net9.0 | 9.0.3 | fixed | 9.0.18 |
| net9.0 | 9.0.15 | fixed | 9.0.18 |
| net10.0 | 10.0.0 | fixed | 10.0.10 |
| net10.0 | 10.0.7 | fixed | 10.0.10 |
| net10.0 | 10.0.6 | fixed | 10.0.10 |
| net462 | 9.0.15 | fixed | 9.0.18 |
| net462 | 8.0.2 | fixed | 8.0.4 |
| net462 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.0 | 8.0.2 | fixed | 8.0.4 |
| netstandard2.0 | 9.0.15 | fixed | 9.0.18 |
| netstandard2.0 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.1 | 9.0.15 | fixed | 9.0.18 |
| netstandard2.1 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.1 | 8.0.2 | fixed | 8.0.4 |
Zeitstrahl
- Zuerst entdeckt
- 2026-07-22
- Zuletzt aktualisiert
- 2026-07-24