CVE-2026-62902
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Summary
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | .NET 10.0 | 10.0.0 < 10.0.11 | affected |
| Microsoft | .NET 8.0 | 8.0.0 < 8.0.30 | affected |
| Microsoft | .NET 9.0 | 9.0.0 < 9.0.19 | affected |
| Microsoft | Microsoft Visual Studio 2022 version 17.14 | 17.14.0 < 17.14.38 | affected |
| Microsoft | Microsoft Visual Studio 2026 version 18.8 | 18.0 < 18.8.3 | affected |
Weaknesses
- CWE-829: CWE-829: Inclusion of Functionality from Untrusted Control Sphere
- CWE-693: CWE-693: Protection Mechanism Failure
- CWE-918: CWE-918: Server-Side Request Forgery (SSRF)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.