Résumé
Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
Détails de l’avis
Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET TLS/SSL (System.Net.Security). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial of service vulnerability exists in .NET 8, .NET 9, and .NET 10 when processing TLS handshakes. An attacker can send a malformed request and cause application to crash or become unresponsive.
Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/**TBD**
CVSS Details
- Version: 3.1
- Severity: High
- Score: 7.5
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C - Weakness: CWE-1287 (Improper Validation of Specified Type of Input)
Affected Platforms
- Platforms: All
- Architectures: All
Affected Packages
The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below
.NET 10.0
| Package name | Affected version | Patched version |
|---|---|---|
| Microsoft.NetCore.App.Runtime.linux-arm | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.linux-arm64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.linux-musl-x64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.linux-x64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.osx-arm64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.osx-x64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.win-arm | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.win-arm64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.win-x64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.win-x86 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
.NET 9.0
| Package name | Affected version | Patched version |
|---|---|---|
| Microsoft.NetCore.App.Runtime.linux-arm | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.linux-arm64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.linux-musl-x64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.linux-x64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.osx-arm64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.osx-x64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.win-arm | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.win-arm64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.win-x64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.win-x86 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
.NET 8.0
| Package name | Affected version | Patched version |
|---|---|---|
| Microsoft.NetCore.App.Runtime.linux-arm | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.linux-arm64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.linux-musl-x64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.linux-x64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.osx-arm64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.osx-x64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.win-arm | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.win-arm64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.win-x64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.win-x86 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
Advisory FAQ
How do I know if I am affected?
If using a package listed in affected packages, you're exposed to the vulnerability.
How do I fix the issue?
- To fix the issue please install the latest version of .NET. If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
- If your application references the vulnerable nuget package, update the package reference to the patched version. You can list the versions you have installed by running the
dotnet --infocommand.
Once you have installed t
Références
- https://github.com/advisories/GHSA-w7cw-xp7h-6j5j
- https://github.com/dotnet/runtime/security/advisories/GHSA-w7cw-xp7h-6j5j
- https://nvd.nist.gov/vuln/detail/CVE-2026-50524
- https://github.com/dotnet/announcements/issues/413
- https://github.com/dotnet/runtime/issues/130710
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50524
Vulnérabilités liées
Tout Supply chain →- HIGHGHSA-7q9c-hpx7-9cwm
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
- CRITICALCVE-2026-73842
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
- MEDIUMCVE-2026-73557
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
- MEDIUMCVE-2026-73556
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
- MEDIUMCVE-2026-73555
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
- MEDIUMCVE-2026-71486
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds