Описание
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
A flaw was found in .NET. An authorized attacker can exploit this vulnerability by leveraging improper encoding or escaping of output. This allows the attacker to perform spoofing over a network, potentially deceiving users or systems into believing they are interacting with a trusted entity.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/udi-rhel9 | Affected | ||
| Red Hat Enterprise Linux 10 | dotnet8.0 | Fixed | RHSA-2026:41893 | 20.07.2026 |
| Red Hat Enterprise Linux 10 | dotnet9.0 | Fixed | RHSA-2026:41895 | 20.07.2026 |
| Red Hat Enterprise Linux 10 | dotnet10.0 | Fixed | RHSA-2026:41897 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet9.0 | Fixed | RHSA-2026:41899 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet10.0 | Fixed | RHSA-2026:41900 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet8.0 | Fixed | RHSA-2026:41901 | 20.07.2026 |
| Red Hat Enterprise Linux 9 | dotnet8.0 | Fixed | RHSA-2026:41894 | 20.07.2026 |
| Red Hat Enterprise Linux 9 | dotnet9.0 | Fixed | RHSA-2026:41896 | 20.07.2026 |
| Red Hat Enterprise Linux 9 | dotnet10.0 | Fixed | RHSA-2026:41898 | 20.07.2026 |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
Уязвимость программной платформы Microsoft .NET, связанная с неправильным кодированием или экранированием выходных данных, позволяющая нарушителю осуществить SSRF-атаку
6.5 Medium
CVSS3