<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:29:21 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:41893 — Important: .NET 8.0 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:41893</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: aspnetcore-runtime-8.0, AlmaLinux:10: aspnetcore-runtime-dbg-8.0, AlmaLinux:10: aspnetcore-targeting-pack-8.0, AlmaLinux:10: dotnet-apphost-pack-8.0, AlmaLinux:10: dotnet-hostfxr-8.0, AlmaLinux:10: dotnet-runtime-8.0, AlmaLinux:10: dotnet-runtime-dbg-8.0, AlmaLinux:10: dotnet-sdk-8.0, AlmaLinux:10: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:10: dotnet-sdk-dbg-8.0 and 2 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
  * dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
  * ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
  * ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
  * ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
  * dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
  * dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
  * dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
  * dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
  * dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
  * dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
  * dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
  * dotnet: .NET: Denial of Service due to uncontrolled re…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: aspnetcore-runtime-8.0, AlmaLinux:10: aspnetcore-runtime-dbg-8.0, AlmaLinux:10: aspnetcore-targeting-pack-8.0, AlmaLinux:10: dotnet-apphost-pack-8.0, AlmaLinux:10: dotnet-hostfxr-8.0, AlmaLinux:10: dotnet-runtime-8.0, AlmaLinux:10: dotnet-runtime-dbg-8.0, AlmaLinux:10: dotnet-sdk-8.0, AlmaLinux:10: dotnet-sdk-8.0-source-built-artifacts, AlmaLinux:10: dotnet-sdk-dbg-8.0 and 2 more&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)
  * dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)
  * ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)
  * ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)
  * ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)
  * dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)
  * dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)
  * dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)
  * dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)
  * dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)
  * dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)
  * dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)
  * dotnet: .NET: Denial of Service due to uncontrolled re…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:41893</guid>
    </item>
    <item>
      <title>bdu:2026-09820</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09820</link>
      <description>bdu:2026-09820</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09820</guid>
    </item>
    <item>
      <title>BIT-dotnet-2026-50648 — .NET Framework Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/bit-dotnet-2026-50648</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: dotnet&lt;/p&gt;
&lt;p&gt;Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: dotnet&lt;/p&gt;
&lt;p&gt;Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-dotnet-2026-50648</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0869 — De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaqua…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0869</link>
      <description>certfr-2026-avi-0869</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0869</guid>
    </item>
    <item>
      <title>EUVD-2026-376854</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-376854</link>
      <description>EUVD-2026-376854</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-376854</guid>
    </item>
    <item>
      <title>fkie_cve-2026-50648</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50648</link>
      <description>&lt;p&gt;Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-50648</guid>
    </item>
    <item>
      <title>GHSA-23rf-6693-g89p — Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-23rf-6693-g89p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: System.Security.Cryptography.Xml&lt;/p&gt;
&lt;p&gt;## Executive summary&lt;/p&gt;
&lt;p&gt;Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.&lt;/p&gt;
&lt;p&gt;A denial of service vulnerability exists in the XML encryption implementation (EncryptedXml) in .NET 8, .NET 9, and .NET 10. An attacker could exploit this vulnerability by supplying crafted encrypted XML that causes uncontrolled resource consumption, resulting in denial of service.&lt;/p&gt;
&lt;p&gt;## Announcement&lt;/p&gt;
&lt;p&gt;Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/416&lt;/p&gt;
&lt;p&gt;## CVSS Details&lt;/p&gt;
&lt;p&gt;- **Version:** 3.1
- **Severity:** High
- **Score:** 7.5
- **Vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`
- **Weakness:** CWE-770 (Allocation of Resources Without Limits or Throttling)&lt;/p&gt;
&lt;p&gt;## Affected Platforms&lt;/p&gt;
&lt;p&gt;- **Platforms:** All
- **Architectures:** All&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-packages&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected Packages
The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;.NET 10.0&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;.NET 10.0
Package name | Affected version | Patched version
------------ | ---------------- | -------------------------
[System.Security.Cryptography.Xml](https://www.nuget.org/packages/System.Security.Cryptography.Xml)               | &amp;gt;= 10.0.0, &amp;lt;= 10.0.9 | 10.0.10&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;.NET 9.0&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;.NET 9.0
Package name | Affected v…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: System.Security.Cryptography.Xml&lt;/p&gt;
&lt;p&gt;## Executive summary&lt;/p&gt;
&lt;p&gt;Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML Encryption (System.Security.Cryptography.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.&lt;/p&gt;
&lt;p&gt;A denial of service vulnerability exists in the XML encryption implementation (EncryptedXml) in .NET 8, .NET 9, and .NET 10. An attacker could exploit this vulnerability by supplying crafted encrypted XML that causes uncontrolled resource consumption, resulting in denial of service.&lt;/p&gt;
&lt;p&gt;## Announcement&lt;/p&gt;
&lt;p&gt;Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/416&lt;/p&gt;
&lt;p&gt;## CVSS Details&lt;/p&gt;
&lt;p&gt;- **Version:** 3.1
- **Severity:** High
- **Score:** 7.5
- **Vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`
- **Weakness:** CWE-770 (Allocation of Resources Without Limits or Throttling)&lt;/p&gt;
&lt;p&gt;## Affected Platforms&lt;/p&gt;
&lt;p&gt;- **Platforms:** All
- **Architectures:** All&lt;/p&gt;
&lt;p&gt;## &amp;lt;a name=&amp;#34;affected-packages&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;Affected Packages
The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;.NET 10.0&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;.NET 10.0
Package name | Affected version | Patched version
------------ | ---------------- | -------------------------
[System.Security.Cryptography.Xml](https://www.nuget.org/packages/System.Security.Cryptography.Xml)               | &amp;gt;= 10.0.0, &amp;lt;= 10.0.9 | 10.0.10&lt;/p&gt;
&lt;p&gt;### &amp;lt;a name=&amp;#34;.NET 9.0&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;.NET 9.0
Package name | Affected v…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-23rf-6693-g89p</guid>
    </item>
    <item>
      <title>jvndb-2026-032925</title>
      <link>https://cve.radiocsirt.org/vuln/jvndb-2026-032925</link>
      <description>&lt;p&gt;CVE-2026-33842 | Windows File Explorer Information Disclosure Vulnerability&#13;
CVE-2026-34328 | Windows Audio Service Information Disclosure Vulnerability&#13;
CVE-2026-34346 | Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability&#13;
CVE-2026-34348 | Windows Event Logging Service Information Disclosure Vulnerability&#13;
CVE-2026-34349 | Windows Media Information Disclosure Vulnerability&#13;
CVE-2026-40378 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability&#13;
CVE-2026-40400 | Windows PowerShell Remote Code Execution Vulnerability&#13;
CVE-2026-40422 | Windows File Explorer Information Disclosure Vulnerability&#13;
CVE-2026-41087 | Windows File Explorer Information Disclosure Vulnerability&#13;
CVE-2026-42900 | Microsoft Windows App Store Elevation of Privilege Vulnerability&#13;
CVE-2026-42975 | Windows Bluetooth Port Driver Remote Code Execution&#13;
CVE-2026-42982 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability&#13;
CVE-2026-42990 | SQL Server ODBC driver Elevation of Privilege Vulnerability&#13;
CVE-2026-44806 | Windows Secure Channel Denial of Service Vulnerability&#13;
CVE-2026-47302 | .NET Denial of Service Vulnerability&#13;
CVE-2026-48564 | DHCP Server Service Remote Code Execution Vulnerability&#13;
CVE-2026-49164 | Windows Active Directory Domain Services Remote Code Execution Vulnerability&#13;
CVE-2026-49165 | Microsoft Windows App Store Information Disclosure Vulnerability&#13;
CVE-2026-49167 | Windows Kernel Elevation of Privilege Vulner…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CVE-2026-33842 | Windows File Explorer Information Disclosure Vulnerability&#13;
CVE-2026-34328 | Windows Audio Service Information Disclosure Vulnerability&#13;
CVE-2026-34346 | Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability&#13;
CVE-2026-34348 | Windows Event Logging Service Information Disclosure Vulnerability&#13;
CVE-2026-34349 | Windows Media Information Disclosure Vulnerability&#13;
CVE-2026-40378 | Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability&#13;
CVE-2026-40400 | Windows PowerShell Remote Code Execution Vulnerability&#13;
CVE-2026-40422 | Windows File Explorer Information Disclosure Vulnerability&#13;
CVE-2026-41087 | Windows File Explorer Information Disclosure Vulnerability&#13;
CVE-2026-42900 | Microsoft Windows App Store Elevation of Privilege Vulnerability&#13;
CVE-2026-42975 | Windows Bluetooth Port Driver Remote Code Execution&#13;
CVE-2026-42982 | Windows Secure Kernel Mode Elevation of Privilege Vulnerability&#13;
CVE-2026-42990 | SQL Server ODBC driver Elevation of Privilege Vulnerability&#13;
CVE-2026-44806 | Windows Secure Channel Denial of Service Vulnerability&#13;
CVE-2026-47302 | .NET Denial of Service Vulnerability&#13;
CVE-2026-48564 | DHCP Server Service Remote Code Execution Vulnerability&#13;
CVE-2026-49164 | Windows Active Directory Domain Services Remote Code Execution Vulnerability&#13;
CVE-2026-49165 | Microsoft Windows App Store Information Disclosure Vulnerability&#13;
CVE-2026-49167 | Windows Kernel Elevation of Privilege Vulner…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/jvndb-2026-032925</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-50648 — .NET Framework Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-50648</link>
      <description>msrc_CVE-2026-50648</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-50648</guid>
    </item>
    <item>
      <title>NCSC-2026-0235 — Kwetsbaarheden verholpen in Microsoft Developer Tools</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0235</link>
      <description>NCSC-2026-0235</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0235</guid>
    </item>
    <item>
      <title>RHSA-2026:26638 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:26638</link>
      <description>&lt;p&gt;dotnet: .NET: Local file tampering via link following vulnerability dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass dotnet: .NET Framework: Denial of Service via improper input validation dotnet: .NET: Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local tampering via improper link resolution dotnet: .NET Framework: Denial of Service via network-based buffer overflow dotnet: .NET: Security feature bypass due to incorrect authorization dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM .NET: .NET: Network Spoofing Vulnerability ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation dotnet: .NET Core: Denial of Service via type confusion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;dotnet: .NET: Local file tampering via link following vulnerability dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption ws: ws: Uninitialized memory disclosure via `websocket.close()` with `TypedArray` ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass dotnet: .NET Framework: Denial of Service via improper input validation dotnet: .NET: Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local tampering via improper link resolution dotnet: .NET Framework: Denial of Service via network-based buffer overflow dotnet: .NET: Security feature bypass due to incorrect authorization dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM .NET: .NET: Network Spoofing Vulnerability ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation dotnet: .NET Core: Denial of Service via type confusion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:26638</guid>
    </item>
    <item>
      <title>RHSA-2026:41893 — Red Hat Security Advisory: .NET 8.0 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:41893</link>
      <description>&lt;p&gt;ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass dotnet: .NET Security Feature Bypass Vulnerability dotnet: .NET Framework: Denial of Service via improper input validation dotnet: .NET: Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local tampering via improper link resolution dotnet: .NET Framework: Denial of Service via network-based buffer overflow dotnet: .NET: Security feature bypass due to incorrect authorization dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local code execution via deserialization of untrusted data dotnet: .NET Framework: Privilege escalation via code injection dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM .NET: .NET: Network Spoofing Vulnerability ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation dotnet: .NET Core: Denial of Service via type confusion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass dotnet: .NET Security Feature Bypass Vulnerability dotnet: .NET Framework: Denial of Service via improper input validation dotnet: .NET: Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local tampering via improper link resolution dotnet: .NET Framework: Denial of Service via network-based buffer overflow dotnet: .NET: Security feature bypass due to incorrect authorization dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation dotnet: .NET: Local code execution via deserialization of untrusted data dotnet: .NET Framework: Privilege escalation via code injection dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM .NET: .NET: Network Spoofing Vulnerability ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation dotnet: .NET Core: Denial of Service via type confusion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:41893</guid>
    </item>
    <item>
      <title>RLSA-2026:41893 — Important: .NET 8.0 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:41893</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: dotnet8.0&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)&lt;/p&gt;
&lt;p&gt;* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)&lt;/p&gt;
&lt;p&gt;* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)&lt;/p&gt;
&lt;p&gt;* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (C…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:10: dotnet8.0&lt;/p&gt;
&lt;p&gt;.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.&lt;/p&gt;
&lt;p&gt;New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK 8.0.129 and .NET Runtime 8.0.29.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108)&lt;/p&gt;
&lt;p&gt;* ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170)&lt;/p&gt;
&lt;p&gt;* ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300)&lt;/p&gt;
&lt;p&gt;* ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646)&lt;/p&gt;
&lt;p&gt;* dotnet: .NET: Denial of Service due to uncontrolled resource allocation (C…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:41893</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-50648</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50648</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7, Ubuntu:22.04:LTS: dotnet8, Ubuntu:24.04:LTS: dotnet10, Ubuntu:24.04:LTS: dotnet8, Ubuntu:26.04:LTS: dotnet10&lt;/p&gt;
&lt;p&gt;Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:22.04:LTS: dotnet6, Ubuntu:22.04:LTS: dotnet7, Ubuntu:22.04:LTS: dotnet8, Ubuntu:24.04:LTS: dotnet10, Ubuntu:24.04:LTS: dotnet8, Ubuntu:26.04:LTS: dotnet10&lt;/p&gt;
&lt;p&gt;Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50648</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2324 — Microsoft DeveloperTools: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2324</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio Code, .NET Framework, Microsoft .NET, Visual Studio 2022 und Visual Studio 2026 ausnutzen, um erweiterte Berechtigungen, einschließlich Administratorrechte, zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen, einen Denial-of-Service-Zustand auszulösen oder Spoofing-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Microsoft Visual Studio Code, .NET Framework, Microsoft .NET, Visual Studio 2022 und Visual Studio 2026 ausnutzen, um erweiterte Berechtigungen, einschließlich Administratorrechte, zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen, einen Denial-of-Service-Zustand auszulösen oder Spoofing-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2324</guid>
    </item>
  </channel>
</rss>
