CVE-2026-47304
설명
- CVE ID
- CVE-2026-47304
- 패키지
- System.Security.Cryptography.Xml
- CVE 심각도
- High
- EPPlus 영향
- Medium
영향을 받은 EPPlus 버전
8.0.1 – 8.6.2
현황
fix-available — 해결책이 있습니다. 자세한 내용은 권고를 참조하세요.
자문
Microsoft has released a security fix for a security feature bypass vulnerability (CVE-2026-47304) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. The vulnerability concerns improper verification of cryptographic signatures, which may allow an invalid signature to be accepted as valid. EPPlus uses this package to create and validate digital signatures for workbooks, including validating the signature of a workbook when it is read. Applications that rely on EPPlus to validate workbook signatures — for example, to determine the authenticity of a workbook of unknown or untrusted origin — should update promptly. As stated in our security profile, the host application remains responsible for deciding whether a file is trusted before passing it to EPPlus.
Update to EPPlus 8.6.3 to resolve this issue.
패키지 수정 정보
이 정보는 EPPlus가 아닌 업스트림 패키지(System.Security.Cryptography.Xml)를 의미합니다. EPPlus구체적인 안내는 위의 권고문을 참고하세요.
| Target framework | 패키지 버전 | 고정 상태 | |
|---|---|---|---|
| net8.0 | 9.0.15 | fixed | 9.0.18 |
| net8.0 | 8.0.3 | fixed | 8.0.4 |
| net8.0 | 8.0.2 | fixed | 8.0.4 |
| net9.0 | 9.0.3 | fixed | 9.0.18 |
| net9.0 | 9.0.15 | fixed | 9.0.18 |
| net10.0 | 10.0.0 | fixed | 10.0.10 |
| net10.0 | 10.0.7 | fixed | 10.0.10 |
| net10.0 | 10.0.6 | fixed | 10.0.10 |
| net462 | 9.0.15 | fixed | 9.0.18 |
| net462 | 8.0.2 | fixed | 8.0.4 |
| net462 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.0 | 8.0.2 | fixed | 8.0.4 |
| netstandard2.0 | 9.0.15 | fixed | 9.0.18 |
| netstandard2.0 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.1 | 9.0.15 | fixed | 9.0.18 |
| netstandard2.1 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.1 | 8.0.2 | fixed | 8.0.4 |
연대표
- 처음 탐지
- 2026-07-22
- 마지막 업데이트
- 2026-07-24