← 返回漏洞列表

CVE-2026-47302

描述
CVE ID
CVE-2026-47302
包装
System.Security.Cryptography.Xml
CVE严重程度
High
EPPlus 影响
Low
受影响 EPPlus 版本

8.0.1 – 8.6.2

现状

fix-available — 有修复方法。详情请参见警示。

咨询

Microsoft has released a security fix for a denial of service vulnerability (CVE-2026-47302) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. EPPlus uses this package to create and validate digital signatures for workbooks. The risk for EPPlus users is considered very low, as EPPlus does not expose any way for an external attacker to control the input passed to the affected library. The package is only used to process workbooks that the EPPlus user has either created themselves or chosen to open as trusted.


Update to EPPlus 8.6.3 to resolve this issue.

包修复信息

该信息指的是上游封装(System.Security.Cryptography.Xml),而非 EPPlus。请参阅上方的建议, EPPlus具体指导。

Target framework 包版本 固定状态 版本修正
net8.0 9.0.15 fixed 9.0.18
net8.0 8.0.3 fixed 8.0.4
net8.0 8.0.2 fixed 8.0.4
net9.0 9.0.3 fixed 9.0.18
net9.0 9.0.15 fixed 9.0.18
net10.0 10.0.0 fixed 10.0.10
net10.0 10.0.7 fixed 10.0.10
net10.0 10.0.6 fixed 10.0.10
net462 9.0.15 fixed 9.0.18
net462 8.0.2 fixed 8.0.4
net462 8.0.3 fixed 8.0.4
netstandard2.0 8.0.2 fixed 8.0.4
netstandard2.0 9.0.15 fixed 9.0.18
netstandard2.0 8.0.3 fixed 8.0.4
netstandard2.1 9.0.15 fixed 9.0.18
netstandard2.1 8.0.3 fixed 8.0.4
netstandard2.1 8.0.2 fixed 8.0.4
时间线
首次检测
2026-07-22
最后更新
2026-07-24
← 返回漏洞列表