← Torna all'elenco delle vulnerabilità

CVE-2026-50527

Descrizione
CVE ID
CVE-2026-50527
Pacchetto
System.Security.Cryptography.Xml
Gravità della CVE
High
EPPlus impatto
Low
Versioni EPPlus interessate

8.0.1 – 8.6.2

Stato

fix-available — Una soluzione è disponibile. Vedi l'avviso per i dettagli.

Advisory

Microsoft has released a security fix for a denial of service vulnerability (CVE-2026-50527) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. EPPlus uses this package to create and validate digital signatures for workbooks. The risk for EPPlus users is considered very low, as EPPlus does not expose any way for an external attacker to control the input passed to the affected library. The package is only used to process workbooks that the EPPlus user has either created themselves or chosen to open as trusted.

Update to EPPlus 8.6.3 to resolve this issue.

Informazioni sulla correzione del pacchetto

Queste informazioni si riferiscono al pacchetto upstream (System.Security.Cryptography.Xml), non EPPlus. Consulta l'avviso sopra per indicazioni specifiche per EPPlus.

Target framework Versione del pacchetto Stato fisso Corretto nella versione
net8.0 9.0.15 fixed 9.0.18
net8.0 8.0.3 fixed 8.0.4
net8.0 8.0.2 fixed 8.0.4
net9.0 9.0.3 fixed 9.0.18
net9.0 9.0.15 fixed 9.0.18
net10.0 10.0.0 fixed 10.0.10
net10.0 10.0.7 fixed 10.0.10
net10.0 10.0.6 fixed 10.0.10
net462 9.0.15 fixed 9.0.18
net462 8.0.2 fixed 8.0.4
net462 8.0.3 fixed 8.0.4
netstandard2.0 8.0.2 fixed 8.0.4
netstandard2.0 9.0.15 fixed 9.0.18
netstandard2.0 8.0.3 fixed 8.0.4
netstandard2.1 9.0.15 fixed 9.0.18
netstandard2.1 8.0.3 fixed 8.0.4
netstandard2.1 8.0.2 fixed 8.0.4
Cronologia
Prima rilevazione
2026-07-23
Ultimo aggiornamento
2026-07-24
← Torna all'elenco delle vulnerabilità