← Voltar à lista de vulnerabilidades

CVE-2026-47304

Descrição
CVE ID
CVE-2026-47304
Pacote
System.Security.Cryptography.Xml
Gravidade da ECV
High
EPPlus impacto
Medium
Versões EPPlus Afetadas

8.0.1 – 8.6.2

Status

fix-available — Uma solução está disponível. Consulte o aviso para detalhes.

Consultoria

Microsoft has released a security fix for a security feature bypass vulnerability (CVE-2026-47304) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. The vulnerability concerns improper verification of cryptographic signatures, which may allow an invalid signature to be accepted as valid. EPPlus uses this package to create and validate digital signatures for workbooks, including validating the signature of a workbook when it is read. Applications that rely on EPPlus to validate workbook signatures — for example, to determine the authenticity of a workbook of unknown or untrusted origin — should update promptly. As stated in our security profile, the host application remains responsible for deciding whether a file is trusted before passing it to EPPlus.


Update to EPPlus 8.6.3 to resolve this issue.


Informações sobre Correção de Pacotes

Essa informação refere-se ao pacote upstream (System.Security.Cryptography.Xml), não EPPlus. Veja o aviso acima para orientações específicas EPPlus.

Target framework Versão do pacote Estado fixo Corrigido na versão
net8.0 9.0.15 fixed 9.0.18
net8.0 8.0.3 fixed 8.0.4
net8.0 8.0.2 fixed 8.0.4
net9.0 9.0.3 fixed 9.0.18
net9.0 9.0.15 fixed 9.0.18
net10.0 10.0.0 fixed 10.0.10
net10.0 10.0.7 fixed 10.0.10
net10.0 10.0.6 fixed 10.0.10
net462 9.0.15 fixed 9.0.18
net462 8.0.2 fixed 8.0.4
net462 8.0.3 fixed 8.0.4
netstandard2.0 8.0.2 fixed 8.0.4
netstandard2.0 9.0.15 fixed 9.0.18
netstandard2.0 8.0.3 fixed 8.0.4
netstandard2.1 9.0.15 fixed 9.0.18
netstandard2.1 8.0.3 fixed 8.0.4
netstandard2.1 8.0.2 fixed 8.0.4
Linha do tempo
Primeira detecção
2026-07-22
Última atualização
2026-07-24
← Voltar à lista de vulnerabilidades