← Güvenlik açıklığı listesine geri dön

CVE-2026-50648

Tanım
CVE ID
CVE-2026-50648
Paket
System.Security.Cryptography.Xml
CVE şiddeti
High
EPPlus etkisi
Low
Etkilenen EPPlus Versiyonları

8.0.1 – 8.6.2

Durum

fix-available — Bir çözüm mevcut. Detaylar için tavsiyeye bakınız.

Tavsiye

Microsoft has released a security fix for a denial of service vulnerability (CVE-2026-50648) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. EPPlus uses this package to create and validate digital signatures for workbooks. The risk for EPPlus users is considered very low, as EPPlus does not expose any way for an external attacker to control the input passed to the affected library. The package is only used to process workbooks that the EPPlus user has either created themselves or chosen to open as trusted.

Update to EPPlus 8.6.3 to resolve this issue.

Paket Düzeltme Bilgileri

Bu bilgi, EPPlusdeğil, yukarı akış paketine (System.Security.Cryptography.Xml) atıfta bulunur. Yukarıdaki tavsiyeye EPPlusözel rehberlik için bakınız.

Target framework Paket versiyonu Sabit durum Versiyonda düzeltildi
net8.0 9.0.15 fixed 9.0.18
net8.0 8.0.3 fixed 8.0.4
net8.0 8.0.2 fixed 8.0.4
net9.0 9.0.3 fixed 9.0.18
net9.0 9.0.15 fixed 9.0.18
net10.0 10.0.0 fixed 10.0.10
net10.0 10.0.7 fixed 10.0.10
net10.0 10.0.6 fixed 10.0.10
net462 9.0.15 fixed 9.0.18
net462 8.0.2 fixed 8.0.4
net462 8.0.3 fixed 8.0.4
netstandard2.0 8.0.2 fixed 8.0.4
netstandard2.0 9.0.15 fixed 9.0.18
netstandard2.0 8.0.3 fixed 8.0.4
netstandard2.1 9.0.15 fixed 9.0.18
netstandard2.1 8.0.3 fixed 8.0.4
netstandard2.1 8.0.2 fixed 8.0.4
Zaman çizelgesi
İlk tespit edildi
2026-07-22
Son güncelleme
2026-07-24
← Güvenlik açıklığı listesine geri dön