← Voltar à lista de vulnerabilidades

CVE-2026-47302

Descrição
CVE ID
CVE-2026-47302
Pacote
System.Security.Cryptography.Xml
Gravidade da ECV
High
EPPlus impacto
Low
Versões EPPlus Afetadas

8.0.1 – 8.6.2

Status

fix-available — Uma solução está disponível. Consulte o aviso para detalhes.

Consultoria

Microsoft has released a security fix for a denial of service vulnerability (CVE-2026-47302) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. EPPlus uses this package to create and validate digital signatures for workbooks. The risk for EPPlus users is considered very low, as EPPlus does not expose any way for an external attacker to control the input passed to the affected library. The package is only used to process workbooks that the EPPlus user has either created themselves or chosen to open as trusted.


Update to EPPlus 8.6.3 to resolve this issue.

Informações sobre Correção de Pacotes

Essa informação refere-se ao pacote upstream (System.Security.Cryptography.Xml), não EPPlus. Veja o aviso acima para orientações específicas EPPlus.

Target framework Versão do pacote Estado fixo Corrigido na versão
net8.0 9.0.15 fixed 9.0.18
net8.0 8.0.3 fixed 8.0.4
net8.0 8.0.2 fixed 8.0.4
net9.0 9.0.3 fixed 9.0.18
net9.0 9.0.15 fixed 9.0.18
net10.0 10.0.0 fixed 10.0.10
net10.0 10.0.7 fixed 10.0.10
net10.0 10.0.6 fixed 10.0.10
net462 9.0.15 fixed 9.0.18
net462 8.0.2 fixed 8.0.4
net462 8.0.3 fixed 8.0.4
netstandard2.0 8.0.2 fixed 8.0.4
netstandard2.0 9.0.15 fixed 9.0.18
netstandard2.0 8.0.3 fixed 8.0.4
netstandard2.1 9.0.15 fixed 9.0.18
netstandard2.1 8.0.3 fixed 8.0.4
netstandard2.1 8.0.2 fixed 8.0.4
Linha do tempo
Primeira detecção
2026-07-22
Última atualização
2026-07-24
← Voltar à lista de vulnerabilidades