Details:
.NET is a managed-software framework. It implements a subset of the .NET framework APIs and several new APIs, and it includes a CLR implementation.
New versions of .NET that address a security vulnerability are now available. The updated versions are .NET SDK SDK_VERSION and .NET Runtime RUNTIME_VERSION.Security Fix(es):
dotnet: .NET: Security Bypass and Denial of Service Vulnerability (CVE-2026-26171)
dotnet: .NET: Denial of Service via stack overflow (CVE-2026-32203)
dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform (CVE-2026-33116)
dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw (CVE-2026-32178)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
0:8.0.26-1.el8_100:8.0.26-1.el8_100:8.0.26-1.el8_100:8.0.26-1.el8_100:8.0.26-1.el8_100:8.0.26-1.el8_100:8.0.26-1.el8_100:8.0.26-1.el8_100:8.0.26-1.el8_100:8.0.26-1.el8_10Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:NI:NA:H7.5/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H