<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T01:41:02.908486+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:6521</id>
    <title>ALSA-2022:6521 — Moderate: .NET 6.0 security and bugfix update</title>
    <updated>2026-10-03T01:41:03.124311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: aspnetcore-runtime-6.0, AlmaLinux:9: aspnetcore-targeting-pack-6.0, AlmaLinux:9: dotnet-apphost-pack-6.0, AlmaLinux:9: dotnet-host, AlmaLinux:9: dotnet-hostfxr-6.0, AlmaLinux:9: dotnet-runtime-6.0, AlmaLinux:9: dotnet-sdk-6.0, AlmaLinux:9: dotnet-sdk-6.0-source-built-artifacts, AlmaLinux:9: dotnet-targeting-pack-6.0, AlmaLinux:9: dotnet-templates-6.0 and 1 more</p>
<p>.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.</p>
<p>New versions of .NET that address a security vulnerability are now available. The updated versions are .NET 6.0 to SDK 6.0.109 and Runtime 6.0.9.</p>
<p>Security Fix(es):</p>
<p>* dotnet: DenialOfService - ASP.NET Core MVC vulnerable to stack overflow via ModelStateDictionary recursion. (CVE-2022-38013)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:6521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-06584</id>
    <title>bdu:2023-06584</title>
    <updated>2026-10-03T01:41:03.124395+00:00</updated>
    <content>bdu:2023-06584</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-06584"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-dotnet-2022-38013</id>
    <title>BIT-dotnet-2022-38013 — .NET Core and Visual Studio Denial of Service Vulnerability</title>
    <updated>2026-10-03T01:41:03.124413+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: dotnet</p>
<p>.NET Core and Visual Studio Denial of Service Vulnerability</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-dotnet-2022-38013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-840</id>
    <title>certfr-2022-avi-840 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Microsoft .Net&lt;/span&gt;. Elles permettent à un at…</title>
    <updated>2026-10-03T01:41:03.124434+00:00</updated>
    <content>certfr-2022-avi-840</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-840"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2024-jx92340</id>
    <title>CLEANSTART-2024-JX92340 — .NET Core and Visual Studio Denial of Service Vulnerability</title>
    <updated>2026-10-03T01:41:03.124450+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: dotnet6-build, CleanStart: dotnet6-runtime</p>
<p>CVE-2022-38013 affects multiple packages. . See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2024-jx92340"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-321961</id>
    <title>EUVD-2026-321961</title>
    <updated>2026-10-03T01:41:03.124471+00:00</updated>
    <content>EUVD-2026-321961</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-321961"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-38013</id>
    <title>fkie_cve-2022-38013</title>
    <updated>2026-10-03T01:41:03.124483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>.NET Core and Visual Studio Denial of Service Vulnerability</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-38013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r8m2-4x37-6592</id>
    <title>GHSA-r8m2-4x37-6592 — .NET Denial of Service Vulnerability</title>
    <updated>2026-10-03T01:41:03.124502+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> NuGet: Microsoft.AspNetCore.App.Runtime.linux-arm, NuGet: Microsoft.AspNetCore.App.Runtime.linux-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-musl-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-musl-x64, NuGet: Microsoft.AspNetCore.App.Runtime.linux-x64, NuGet: Microsoft.AspNetCore.App.Runtime.osx-x64, NuGet: Microsoft.AspNetCore.App.Runtime.win-arm, NuGet: Microsoft.AspNetCore.App.Runtime.win-arm64, NuGet: Microsoft.AspNetCore.App.Runtime.win-x64, NuGet: Microsoft.AspNetCore.App.Runtime.win-x86 and 2 more</p>
<p>Microsoft is releasing this security advisory to provide information about a vulnerability in .NET Core 3.1 and .NET 6.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.</p>
<p>A denial of service vulnerability exists in ASP.NET Core 3.1 and .NET 6.0 where a malicious client could cause a stack overflow which may result in a denial of service attack when an attacker sends a customized payload that is parsed during model binding.</p>
<p>## &lt;a name="affected-software"&gt;&lt;/a&gt;Affected software
* Any .NET 6.0 application running on .NET 6.0.8 or earlier.
* Any ASP.NET Core 3.1 application running on .NET Core 3.1.28 or earlier.
If your application uses the following package versions, ensure you update to the latest version of .NET.
### &lt;a name="ASP.NET Core 3.1"&gt;&lt;/a&gt;.NET Core 3.1
Package name | Affected version | Patched version
------------ | ---------------- | -------------------------
[Microsoft.AspNetCore.App.Runtime.linux-arm](https://www.nuget.org/packages/Microsoft.AspNetCore.App.Runtime.linux-arm)|&gt;= 3.1.0, &lt; 3.1.29|3.1.29
[Microsoft.AspNetCore.App.Runtime.linux-arm64](https://www.nuget.org/packages/Microsoft.AspNetCore.App.Runtime.linux-arm64)|&gt;= 3.1.0, &lt; 3.1.29|3.1.29
[Microsoft.AspNetCore.App.Runtime.linux-musl-arm64](https://www.nuget.org/packages/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64)|&gt;= 3.1.0, &lt; 3.1.29|3.1.29
[Microsoft.AspNetCore.App.Runtime.linux-musl-x64](https://www.nuget.org/packages/Micros…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r8m2-4x37-6592"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-38013</id>
    <title>gsd-2022-38013</title>
    <updated>2026-10-03T01:41:03.124619+00:00</updated>
    <content>gsd-2022-38013</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-38013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2022-38013</id>
    <title>msrc_CVE-2022-38013 — .NET Core and Visual Studio Denial of Service Vulnerability</title>
    <updated>2026-10-03T01:41:03.124632+00:00</updated>
    <content>msrc_CVE-2022-38013</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2022-38013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6520</id>
    <title>RHSA-2022:6520 — Red Hat Security Advisory: .NET 6.0 on RHEL 7 security and bugfix update</title>
    <updated>2026-10-03T01:41:03.124649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: DenialOfService - ASP.NET Core MVC vulnerable to stack overflow via ModelStateDictionary recursion.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6520"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:6521</id>
    <title>RHSA-2022:6521 — Red Hat Security Advisory: .NET 6.0 security and bugfix update</title>
    <updated>2026-10-03T01:41:03.124666+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>dotnet: DenialOfService - ASP.NET Core MVC vulnerable to stack overflow via ModelStateDictionary recursion.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:6521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-38013</id>
    <title>UBUNTU-CVE-2022-38013</title>
    <updated>2026-10-03T01:41:03.124682+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: dotnet6</p>
<p>.NET Core and Visual Studio Denial of Service Vulnerability</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-38013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1403</id>
    <title>WID-SEC-W-2022-1403 — Microsoft Developer Tools: Mehrere Schwachstellen</title>
    <updated>2026-10-03T01:41:03.124699+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Microsoft .NET Framework, Microsoft Visual Studio und Microsoft Visual Studio Code ausnutzen, um seine Privilegien zu erweitern, einen Denial-of-Service-Zustand zu verursachen und beliebigen Code auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1403"/>
  </entry>
</feed>
