RHSA-2026:8475HighCVSS 7.5
Red Hat Security Advisory: .NET 9.0 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-26171 — dotnet: .NET: Security Bypass and Denial of Service Vulnerability CVE-2026-32178 — dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw CVE-2026-32203 — dotnet: .NET: Denial of Service via stack overflow CVE-2026-33116 — dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:8475
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457739
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457740
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457741
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2457781
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_8475.json