Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32178

Опубликовано: 14 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

A flaw was found in the .NET runtime (System.Net.Mail) in how email address data is parsed. Improper neutralization of special characters, specifically carriage return and line feed (CR/LF) sequences, may allow specially crafted email address input to be interpreted incorrectly. An attacker could exploit this issue to perform email spoofing by injecting additional headers or altering how the email address is processed during SMTP operations

Отчет

This Important flaw in the .NET runtime's System.Net.Mail component affects Red Hat Enterprise Linux and Red Hat Hardened Images. Improper neutralization of carriage return and line feed sequences during email address parsing can lead to SMTP command or header injection, enabling email spoofing in applications utilizing the affected .NET versions for SMTP operations. The impact is primarily related to how email data is handled and interpreted. By injecting crafted header content, an attacker may influence the structure of email messages and potentially expose sensitive information included in those messages to unintended recipients.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.

Дополнительная информация

Статус:

Important
Дефект:
CWE-138
https://bugzilla.redhat.com/show_bug.cgi?id=2457781dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw

EPSS

Процентиль: 81%
0.02279
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 7.5
nvd
4 месяца назад

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 7.5
msrc
4 месяца назад

.NET Spoofing Vulnerability

github
4 месяца назад

Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость программной платформы .NET, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 81%
0.02279
Низкий

7.5 High

CVSS3