← Powrót do listy podatności

CVE-2026-47304

Opis
CVE ID
CVE-2026-47304
Pakiet
System.Security.Cryptography.Xml
Nasilenie CVE
High
EPPlus wpływ
Medium
Wersje EPPlus dotknięte

8.0.1 – 8.6.2

Status

fix-available — Istnieje rozwiązanie. Szczegóły można znaleźć w artykule informacyjnym.

Doradztwo

Microsoft has released a security fix for a security feature bypass vulnerability (CVE-2026-47304) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. The vulnerability concerns improper verification of cryptographic signatures, which may allow an invalid signature to be accepted as valid. EPPlus uses this package to create and validate digital signatures for workbooks, including validating the signature of a workbook when it is read. Applications that rely on EPPlus to validate workbook signatures — for example, to determine the authenticity of a workbook of unknown or untrusted origin — should update promptly. As stated in our security profile, the host application remains responsible for deciding whether a file is trusted before passing it to EPPlus.


Update to EPPlus 8.6.3 to resolve this issue.


Informacje o naprawach pakietu

Informacje te dotyczą pakietu upstream (System.Security.Cryptography.Xml), a nie EPPlus. Zobacz powyższe ostrzeżenie, aby uzyskać wskazówki dotyczące EPPlus-.

Target framework Wersja pakietu Stan stały Wersja poprawiona
net8.0 9.0.15 fixed 9.0.18
net8.0 8.0.3 fixed 8.0.4
net8.0 8.0.2 fixed 8.0.4
net9.0 9.0.3 fixed 9.0.18
net9.0 9.0.15 fixed 9.0.18
net10.0 10.0.0 fixed 10.0.10
net10.0 10.0.7 fixed 10.0.10
net10.0 10.0.6 fixed 10.0.10
net462 9.0.15 fixed 9.0.18
net462 8.0.2 fixed 8.0.4
net462 8.0.3 fixed 8.0.4
netstandard2.0 8.0.2 fixed 8.0.4
netstandard2.0 9.0.15 fixed 9.0.18
netstandard2.0 8.0.3 fixed 8.0.4
netstandard2.1 9.0.15 fixed 9.0.18
netstandard2.1 8.0.3 fixed 8.0.4
netstandard2.1 8.0.2 fixed 8.0.4
Oś czasu
Pierwszy wykryty
2026-07-22
Ostatnia aktualizacja
2026-07-24
← Powrót do listy podatności