Skip to content

Upgrade System.Security.Cryptography.Xml to 10.0.6#25279

Merged
EngincanV merged 9 commits intorel-10.3from
upgrade/system-security-cryptography-xml-10.0.6
Apr 16, 2026
Merged

Upgrade System.Security.Cryptography.Xml to 10.0.6#25279
EngincanV merged 9 commits intorel-10.3from
upgrade/system-security-cryptography-xml-10.0.6

Conversation

@maliming
Copy link
Copy Markdown
Member

Fix CVE-2026-26171 (GHSA-w3x6-4m5h-cxqf) high severity vulnerability in System.Security.Cryptography.Xml package, which is a transitive dependency of Hangfire.AspNetCore via Microsoft.AspNetCore.AntiforgeryMicrosoft.AspNetCore.DataProtection under netstandard2.0/2.1.

Closes #25278

Copilot AI review requested due to automatic review settings April 16, 2026 04:03
@maliming maliming added the dependency-change Indicates a version change of a dependency (typically, upgrade) label Apr 16, 2026
@maliming maliming added this to the 10.3-patch milestone Apr 16, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the centrally-managed System.Security.Cryptography.Xml NuGet version to address CVE-2026-26171 (GHSA-w3x6-4m5h-cxqf), and records the change in the package version change log.

Changes:

  • Bump System.Security.Cryptography.Xml from 10.0.2 to 10.0.6 via central package management.
  • Add a changelog entry documenting the package upgrade for the 10.3.0 release notes.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
Directory.Packages.props Updates the centrally pinned version of System.Security.Cryptography.Xml to 10.0.6.
docs/en/package-version-changes.md Documents the version bump in the package version changes table.

@maliming maliming requested a review from EngincanV April 16, 2026 04:23
@EngincanV EngincanV merged commit 9b381fa into rel-10.3 Apr 16, 2026
4 of 5 checks passed
@EngincanV EngincanV deleted the upgrade/system-security-cryptography-xml-10.0.6 branch April 16, 2026 06:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependency-change Indicates a version change of a dependency (typically, upgrade)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants