CVE-2026-50527
描述
- CVE ID
- CVE-2026-50527
- 包装
- System.Security.Cryptography.Xml
- CVE严重程度
- High
- EPPlus 影响
- Low
受影响 EPPlus 版本
8.0.1 – 8.6.2
现状
fix-available — 有修复方法。详情请参见警示。
咨询
Microsoft has released a security fix for a denial of service vulnerability (CVE-2026-50527) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. EPPlus uses this package to create and validate digital signatures for workbooks. The risk for EPPlus users is considered very low, as EPPlus does not expose any way for an external attacker to control the input passed to the affected library. The package is only used to process workbooks that the EPPlus user has either created themselves or chosen to open as trusted.
Update to EPPlus 8.6.3 to resolve this issue.
包修复信息
该信息指的是上游封装(System.Security.Cryptography.Xml),而非 EPPlus。请参阅上方的建议, EPPlus具体指导。
| Target framework | 包版本 | 固定状态 | 版本修正 |
|---|---|---|---|
| net8.0 | 9.0.15 | fixed | 9.0.18 |
| net8.0 | 8.0.3 | fixed | 8.0.4 |
| net8.0 | 8.0.2 | fixed | 8.0.4 |
| net9.0 | 9.0.3 | fixed | 9.0.18 |
| net9.0 | 9.0.15 | fixed | 9.0.18 |
| net10.0 | 10.0.0 | fixed | 10.0.10 |
| net10.0 | 10.0.7 | fixed | 10.0.10 |
| net10.0 | 10.0.6 | fixed | 10.0.10 |
| net462 | 9.0.15 | fixed | 9.0.18 |
| net462 | 8.0.2 | fixed | 8.0.4 |
| net462 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.0 | 8.0.2 | fixed | 8.0.4 |
| netstandard2.0 | 9.0.15 | fixed | 9.0.18 |
| netstandard2.0 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.1 | 9.0.15 | fixed | 9.0.18 |
| netstandard2.1 | 8.0.3 | fixed | 8.0.4 |
| netstandard2.1 | 8.0.2 | fixed | 8.0.4 |
时间线
- 首次检测
- 2026-07-23
- 最后更新
- 2026-07-24