CVE-2026-47302
概要
- CVE ID
- CVE-2026-47302
- パッケージ
- System.Security.Cryptography.Xml
- CVEの重大度
- High
- EPPlus 影響
- Low
影響を受けたEPPlusバージョン
8.0.1 – 8.6.2
現状
fix-available — 修正方法があります。詳細は勧告をご覧ください。
助言
Microsoft has released a security fix for a denial of service vulnerability (CVE-2026-47302) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. EPPlus uses this package to create and validate digital signatures for workbooks. The risk for EPPlus users is considered very low, as EPPlus does not expose any way for an external attacker to control the input passed to the affected library. The package is only used to process workbooks that the EPPlus user has either created themselves or chosen to open as trusted.
Update to EPPlus 8.6.3 to resolve this issue.
パッケージ修正情報
この情報はEPPlusではなく、アップストリームパッケージ(System.Security.Cryptography.Xml)を指します。EPPlus固有のガイダンスについては、上記のアドバイザリーをご覧ください。
| Target framework | パッケージバージョン | 修正状態 | バージョンでは修正済み |
|---|---|---|---|
| net8.0 | 9.0.15 | fixed | 9.0.18 |
| net8.0 | 8.0.3 | fixed | 8.0.4 |
| net8.0 | 8.0.2 | fixed | 8.0.4 |
| net9.0 | 9.0.3 | fixed | 9.0.18 |
| net9.0 | 9.0.15 | fixed | 9.0.18 |
| net10.0 | 10.0.0 | fixed | 10.0.10 |
| net10.0 | 10.0.7 | fixed | 10.0.10 |
| net10.0 | 10.0.6 | fixed | 10.0.10 |
| net462 | 9.0.15 | fixed | 9.0.18 |
| net462 | 8.0.2 | fixed | 8.0.4 |
| net462 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.0 | 8.0.2 | fixed | 8.0.4 |
| netstandard2.0 | 9.0.15 | fixed | 9.0.18 |
| netstandard2.0 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.1 | 9.0.15 | fixed | 9.0.18 |
| netstandard2.1 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.1 | 8.0.2 | fixed | 8.0.4 |
タイムライン
- 初検出
- 2026-07-22
- 最終更新
- 2026-07-24