CVE-2026-50648
Описание
- CVE ID
- CVE-2026-50648
- Пакет
- System.Security.Cryptography.Xml
- Степень тяжести CVE
- High
- EPPlus влияние
- Low
Затронутые EPPlus версии
8.0.1 – 8.6.2
Статус
fix-available — Доступно решение. Подробности см. в совете.
Консультации
Microsoft has released a security fix for a denial of service vulnerability (CVE-2026-50648) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. EPPlus uses this package to create and validate digital signatures for workbooks. The risk for EPPlus users is considered very low, as EPPlus does not expose any way for an external attacker to control the input passed to the affected library. The package is only used to process workbooks that the EPPlus user has either created themselves or chosen to open as trusted.
Update to EPPlus 8.6.3 to resolve this issue.
Информация о исправлении пакета
Эта информация относится к восходящему пакету (System.Security.Cryptography.Xml), а не EPPlus. См. приведённое выше руководство для EPPlus-специфических рекомендаций.
| Target framework | Версия упаковки | Фиксированное состояние | Исправлено в версии |
|---|---|---|---|
| net8.0 | 9.0.15 | fixed | 9.0.18 |
| net8.0 | 8.0.3 | fixed | 8.0.4 |
| net8.0 | 8.0.2 | fixed | 8.0.4 |
| net9.0 | 9.0.3 | fixed | 9.0.18 |
| net9.0 | 9.0.15 | fixed | 9.0.18 |
| net10.0 | 10.0.0 | fixed | 10.0.10 |
| net10.0 | 10.0.7 | fixed | 10.0.10 |
| net10.0 | 10.0.6 | fixed | 10.0.10 |
| net462 | 9.0.15 | fixed | 9.0.18 |
| net462 | 8.0.2 | fixed | 8.0.4 |
| net462 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.0 | 8.0.2 | fixed | 8.0.4 |
| netstandard2.0 | 9.0.15 | fixed | 9.0.18 |
| netstandard2.0 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.1 | 9.0.15 | fixed | 9.0.18 |
| netstandard2.1 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.1 | 8.0.2 | fixed | 8.0.4 |
Хронология
- Первое обнаружение
- 2026-07-22
- Последнее обновление
- 2026-07-24