NuGet Package Vulnerabilities
Vulnerabilities associated with Microsoft.NetCore.App.Runtime.linux-arm.
Packages
Clear package- Microsoft.ChakraCore247 vulnerabilities
- Magick.NET-Q16-AnyCPU163 vulnerabilities
- Magick.NET-Q16-HDRI-AnyCPU163 vulnerabilities
- Magick.NET-Q8-AnyCPU163 vulnerabilities
- Magick.NET-Q16-HDRI-x86162 vulnerabilities
- Magick.NET-Q16-x86161 vulnerabilities
- Magick.NET-Q8-x86161 vulnerabilities
- Magick.NET-Q16-HDRI-OpenMP-arm64159 vulnerabilities
- Magick.NET-Q16-HDRI-x64159 vulnerabilities
- Magick.NET-Q16-OpenMP-arm64159 vulnerabilities
- Magick.NET-Q16-OpenMP-x64159 vulnerabilities
- Magick.NET-Q16-arm64159 vulnerabilities
- Magick.NET-Q16-HDRI-arm64158 vulnerabilities
- Magick.NET-Q8-OpenMP-arm64158 vulnerabilities
- Magick.NET-Q8-arm64158 vulnerabilities
- Magick.NET-Q8-OpenMP-x64155 vulnerabilities
- Magick.NET-Q16-x64154 vulnerabilities
- Magick.NET-Q8-x64152 vulnerabilities
- Magick.NET-Q16-HDRI-OpenMP-x6495 vulnerabilities
- Magick.NET-Q16-OpenMP-x8667 vulnerabilities
- DotNetNuke.Core36 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-x6427 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-x8626 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.win-arm25 vulnerabilities
- Microsoft.AspNetCore.App.Runtime.linux-x6424 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-50659MEDIUM | Generated title:.NET SMTP Client Spoofing Vulnerability## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Mail). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A spoofing vulnerability exists in the SMTP client implementation (System.Net.Mail) in .NET 8, .NET 9, and .NET 10, where an attacker can spoof messages during message routing. ## Announcement Announcement for this issue ca… CWE-116Jul 14, 2026 | CVSS6.5v3.1 | EPSS0.55% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50651HIGH | .NET Denial of Service Vulnerability## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET HTTP client (System.Net.Http). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in .NET 8, .NET 9, and .NET 10 where an attacker can exploit the HTTP/2 protocol to cause an out-of-memory condition. ## Announcement Announcement for this issue can be found at http… CWE-770Jul 14, 2026 | CVSS7.5v3.1 | EPSS0.84% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50528HIGH | .NET Security Feature Bypass Vulnerability## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A security feature bypass vulnerability exists in .NET 8, .NET 9, and .NET 10 when processing TLS/SSL connections. An attacker can exploit the SslStream implementation to bypass authorization checks during secure communicatio… | CVSS8.2v3.1 | EPSS0.551% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-50524HIGH | .NET Framework Denial of Service Vulnerability## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in .NET 8, .NET 9, and .NET 10 when processing TLS handshakes. An attacker can send a malformed request and cause application to crash or become unresponsive. ## Announcement Announc… CWE-1287Jul 14, 2026 | CVSS7.5v3.1 | EPSS0.634% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-47302HIGH | .NET Denial of Service Vulnerability## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET XML processing (System.Security.Cryptography.Xml, System.Xml). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in .NET 8, .NET 9, and .NET 10 related to XML processing. An attacker can exploit XML encryption handling in XML parsing to cause excessive resource con… CWE-770Jul 14, 2026 | CVSS7.5v3.1 | EPSS1.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-57108HIGH | .NET Denial of Service Vulnerability## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in the .NET runtime cryptography layer (CryptoNative_GetX509NameInfo). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in the .NET 8, .NET 9, and .NET 10 runtime when parsing X.509 certificates. A specially crafted certificate could allow an attacker to cause a denial of… CWE-843Jul 14, 2026 | CVSS7.5v3.1 | EPSS1.11% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-32178HIGH | Generated title:Microsoft .NET System.Net.Mail Email Spoofing Vulnerability## Executive Summary: Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in System.Net.Mail where specially crafted data allows an unauthorized attacker to perform a spoofing attack over the network. ## Announcement Announcement for this issue can be found at https://gith… CWE-138Apr 14, 2026 | CVSS7.5v3.1 | EPSS2.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-26127HIGH | .NET Denial of Service Vulnerability# Microsoft Security Advisory CVE-2026-26127 – .NET Denial of Service Vulnerability ## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0 and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A denial of service vulnerability exists in .NET and Microsoft.Bcl.Memory due to an out-of-bounds read when decoding malformed Base64Url input. ## Anno… CWE-125Mar 10, 2026 | CVSS7.5v3.1 | EPSS2.05% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-26131HIGH | .NET Elevation of Privilege Vulnerability# Microsoft Security Advisory CVE-2026-26131 – .NET Elevation of Privilege Vulnerability ## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An elevation of privilege vulnerability exists in .NET due to improper authorization. Incorrect packaging permissions could allow an attacker to gain elevated … CWE-276Mar 10, 2026 | CVSS7.8v3.1 | EPSS0.359% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-55248MEDIUM | .NET, .NET Framework, and Visual Studio Information Disclosure Vulnerability# Microsoft Security Advisory CVE-2025-55248 | .NET Information Disclosure Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A MITM (man in the middle) attacker may prevent use of TLS between client and SMTP server, forcing client to send da… CWE-326Oct 14, 2025 | CVSS4.8v3.1 | EPSS0.671% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30399HIGH | .NET and Visual Studio Remote Code Execution Vulnerability# Microsoft Security Advisory CVE-2025-30399 | .NET Remote Code Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An attacker could exploit this vulnerability by placing files in particular locations, leading to unintended code execution. #… CWE-426Jun 13, 2025 | CVSS7.5v3.1 | EPSS0.922% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21172HIGH | .NET and Visual Studio Remote Code Execution Vulnerability# Microsoft Security Advisory CVE-2025-21172 | .NET and Visual Studio Remote Code Execution Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An attacker could exploit this vulnerability by loading a specially crafted file in Visual Studio. … | CVSS7.5v3.1 | EPSS1.83% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21176HIGH | .NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability# Microsoft Security Advisory CVE-2025-21176 | .NET and Visual Studio Remote Code Execution Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0 and .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An attacker could exploit this vulnerability by loading a specially crafted file in Visual Studio. … CWE-126Jan 14, 2025 | CVSS8.8v3.1 | EPSS2.35% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21171HIGH | .NET Remote Code Execution Vulnerability# Microsoft Security Advisory CVE-2025-21171 | .NET Remote Code Execution Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An attacker could exploit this vulnerability by sending a specially crafted request to the vulnerable web server. ## Announcement… CWE-122Jan 14, 2025 | CVSS7.5v3.1 | EPSS1.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
.NET and Visual Studio Information Disclosure Vulnerability# Microsoft Security Advisory CVE-2024-38167 | .NET Information Disclosure Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A vulnerability exists in .NET runtime TlsStream which may result in Information Disclosure. ## Discussion Discussion for this… CWE-319Aug 13, 2024 | CVSS-v4.0 | EPSS1.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
.NET and Visual Studio Denial of Service Vulnerability# Microsoft Security Advisory CVE-2024-38095 | .NET Denial of Service Vulnerability ## <a name="executive-summary"></a>Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0 and .NET 8.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A Vulnerability exists when System.Formats.Asn1 in .NET parses an X.509 certificate or collection of certificates, a mali… CWE-20Jul 9, 2024 | CVSS-v4.0 | EPSS2.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |