← Powrót do listy podatności

CVE-2026-47302

Opis
CVE ID
CVE-2026-47302
Pakiet
System.Security.Cryptography.Xml
Nasilenie CVE
High
EPPlus wpływ
Low
Wersje EPPlus dotknięte

8.0.1 – 8.6.2

Status

fix-available — Istnieje rozwiązanie. Szczegóły można znaleźć w artykule informacyjnym.

Doradztwo

Microsoft has released a security fix for a denial of service vulnerability (CVE-2026-47302) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. EPPlus uses this package to create and validate digital signatures for workbooks. The risk for EPPlus users is considered very low, as EPPlus does not expose any way for an external attacker to control the input passed to the affected library. The package is only used to process workbooks that the EPPlus user has either created themselves or chosen to open as trusted.


Update to EPPlus 8.6.3 to resolve this issue.

Informacje o naprawach pakietu

Informacje te dotyczą pakietu upstream (System.Security.Cryptography.Xml), a nie EPPlus. Zobacz powyższe ostrzeżenie, aby uzyskać wskazówki dotyczące EPPlus-.

Target framework Wersja pakietu Stan stały Wersja poprawiona
net8.0 9.0.15 fixed 9.0.18
net8.0 8.0.3 fixed 8.0.4
net8.0 8.0.2 fixed 8.0.4
net9.0 9.0.3 fixed 9.0.18
net9.0 9.0.15 fixed 9.0.18
net10.0 10.0.0 fixed 10.0.10
net10.0 10.0.7 fixed 10.0.10
net10.0 10.0.6 fixed 10.0.10
net462 9.0.15 fixed 9.0.18
net462 8.0.2 fixed 8.0.4
net462 8.0.3 fixed 8.0.4
netstandard2.0 8.0.2 fixed 8.0.4
netstandard2.0 9.0.15 fixed 9.0.18
netstandard2.0 8.0.3 fixed 8.0.4
netstandard2.1 9.0.15 fixed 9.0.18
netstandard2.1 8.0.3 fixed 8.0.4
netstandard2.1 8.0.2 fixed 8.0.4
Oś czasu
Pierwszy wykryty
2026-07-22
Ostatnia aktualizacja
2026-07-24
← Powrót do listy podatności