← Volver a la lista de vulnerabilidades

CVE-2026-47302

Descripción
CVE ID
CVE-2026-47302
Paquete
System.Security.Cryptography.Xml
Severidad de la ECV
High
EPPlus impacto
Low
Versiones EPPlus afectadas

8.0.1 – 8.6.2

Estado

fix-available — Hay una solución disponible. Consulte el aviso para más detalles.

Asesoramiento

Microsoft has released a security fix for a denial of service vulnerability (CVE-2026-47302) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. EPPlus uses this package to create and validate digital signatures for workbooks. The risk for EPPlus users is considered very low, as EPPlus does not expose any way for an external attacker to control the input passed to the affected library. The package is only used to process workbooks that the EPPlus user has either created themselves or chosen to open as trusted.


Update to EPPlus 8.6.3 to resolve this issue.

Información sobre la corrección del paquete

Esta información se refiere al paquete upstream (System.Security.Cryptography.Xml), no a EPPlus. Consulta el aviso anterior para orientaciones específicas EPPlus.

Target framework Versión del paquete Estado fijo Corregido en la versión
net8.0 9.0.15 fixed 9.0.18
net8.0 8.0.3 fixed 8.0.4
net8.0 8.0.2 fixed 8.0.4
net9.0 9.0.3 fixed 9.0.18
net9.0 9.0.15 fixed 9.0.18
net10.0 10.0.0 fixed 10.0.10
net10.0 10.0.7 fixed 10.0.10
net10.0 10.0.6 fixed 10.0.10
net462 9.0.15 fixed 9.0.18
net462 8.0.2 fixed 8.0.4
net462 8.0.3 fixed 8.0.4
netstandard2.0 8.0.2 fixed 8.0.4
netstandard2.0 9.0.15 fixed 9.0.18
netstandard2.0 8.0.3 fixed 8.0.4
netstandard2.1 9.0.15 fixed 9.0.18
netstandard2.1 8.0.3 fixed 8.0.4
netstandard2.1 8.0.2 fixed 8.0.4
Cronología
Detectado por primera vez
2026-07-22
Última actualización
2026-07-24
← Volver a la lista de vulnerabilidades