Описание
.NET Security Feature Bypass Vulnerability
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
FAQ
What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could smuggle another HTTP request and bypass front-end security controls or hijack other users' credentials.
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires that the target system be set up in a specific manner and the attacker to have knowledge of that setup.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| .NET 8.0 installed on Windows | ||
| .NET 8.0 installed on Linux | ||
| .NET 8.0 installed on Mac OS | ||
| .NET 9.0 installed on Linux | ||
| .NET 9.0 installed on Mac OS | ||
| .NET 9.0 installed on Windows | ||
| Microsoft Visual Studio 2022 version 17.14 | - | |
| .NET 10.0 installed on Mac OS | ||
| .NET 10.0 installed on Linux | ||
| Microsoft Visual Studio 2026 version 18.8 | - |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
EPSS
5.9 Medium
CVSS3