← 返回漏洞列表

CVE-2026-47304

描述
CVE ID
CVE-2026-47304
包装
System.Security.Cryptography.Xml
CVE严重程度
High
EPPlus 影响
Medium
受影响 EPPlus 版本

8.0.1 – 8.6.2

现状

fix-available — 有修复方法。详情请参见警示。

咨询

Microsoft has released a security fix for a security feature bypass vulnerability (CVE-2026-47304) in System.Security.Cryptography.Xml, addressed in versions 8.0.4, 9.0.18 and 10.0.10. The vulnerability concerns improper verification of cryptographic signatures, which may allow an invalid signature to be accepted as valid. EPPlus uses this package to create and validate digital signatures for workbooks, including validating the signature of a workbook when it is read. Applications that rely on EPPlus to validate workbook signatures — for example, to determine the authenticity of a workbook of unknown or untrusted origin — should update promptly. As stated in our security profile, the host application remains responsible for deciding whether a file is trusted before passing it to EPPlus.


Update to EPPlus 8.6.3 to resolve this issue.


包修复信息

该信息指的是上游封装(System.Security.Cryptography.Xml),而非 EPPlus。请参阅上方的建议, EPPlus具体指导。

Target framework 包版本 固定状态 版本修正
net8.0 9.0.15 fixed 9.0.18
net8.0 8.0.3 fixed 8.0.4
net8.0 8.0.2 fixed 8.0.4
net9.0 9.0.3 fixed 9.0.18
net9.0 9.0.15 fixed 9.0.18
net10.0 10.0.0 fixed 10.0.10
net10.0 10.0.7 fixed 10.0.10
net10.0 10.0.6 fixed 10.0.10
net462 9.0.15 fixed 9.0.18
net462 8.0.2 fixed 8.0.4
net462 8.0.3 fixed 8.0.4
netstandard2.0 8.0.2 fixed 8.0.4
netstandard2.0 9.0.15 fixed 9.0.18
netstandard2.0 8.0.3 fixed 8.0.4
netstandard2.1 9.0.15 fixed 9.0.18
netstandard2.1 8.0.3 fixed 8.0.4
netstandard2.1 8.0.2 fixed 8.0.4
时间线
首次检测
2026-07-22
最后更新
2026-07-24
← 返回漏洞列表