{"cves":[{"id":"CVE-2026-47212","published":"2026-07-14T20:17:00","updated_at":"2026-07-17T19:24:08.792657+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12,\nTwilioRequestParser::doParse() received the configured webhook secret but\nignored the X-Twilio-Signature HMAC header, allowing unauthenticated POST\nrequests to inject forged Twilio status payloads. This issue is fixed in\nversions 6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47212","https://symfony.com/blog/cve-2026-47212-twilio-notifier-webhook-parser-never-verifies-the-x-twilio-signature-hmac-unauthenticated-webhook-event-injection"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45071","published":"2026-07-14T20:17:00","updated_at":"2026-07-17T19:23:47.812290+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12,\nCrawler::addXmlContent() set DOMDocument::$validateOnParse = true before\nloadXML(), re-enabling external entity resolution and allowing\nattacker-supplied XML to expand file:// entities such as local files. This\nissue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45071","https://symfony.com/blog/cve-2026-45071-xxe-local-file-disclosure-in-domcrawler-addxmlcontent-via-validateonparse-true"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45068","published":"2026-07-14T20:17:00","updated_at":"2026-07-17T19:24:22.972425+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12,\nSendmailTransport in -t mode appended recipient addresses to the sendmail\ncommand line without a -- end-of-options separator, allowing an address\nbeginning with - to be interpreted as a sendmail command-line option\ninstead of an address. This issue is fixed in versions 5.4.52, 6.4.40,\n7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45068","https://symfony.com/blog/cve-2026-45068-argument-injection-in-sendmailtransport-via-dash-prefixed-recipient-address"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15714","published":"2026-07-14T20:16:00","updated_at":"2026-07-16T10:54:41.070484+00:00","description":"\nAn out-of-bounds read vulnerability was found in libsoup's multipart\nprocessing subsystem. The flaw exists in the\nsoup_multipart_input_stream_read_headers() function inside\nsoup-multipart-input-stream.c, which does not adequately restrict or\nvalidate the size of incoming multipart boundary strings. When processing a\ncrafted HTTP response containing a malformed or oversized boundary\nparameter, the internal stream reader reads past the allocated buffer\nbounds. A remote, unauthenticated attacker can exploit this behavior to\ncause a service denial (DoS) through application failure or potentially\nread fragments of unauthorized memory metadata.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15714","https://access.redhat.com/security/cve/CVE-2026-15714","https://bugzilla.redhat.com/show_bug.cgi?id=2499942","https://gitlab.gnome.org/GNOME/libsoup/-/work_items/542"],"bugs":[""],"patches":{"libsoup2.4":[],"libsoup3":[]},"tags":{},"packages":[{"name":"libsoup2.4","source":"https://ubuntu.com/security/cve?package=libsoup2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup2.4","debian":"https://tracker.debian.org/pkg/libsoup2.4","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libsoup3","source":"https://ubuntu.com/security/cve?package=libsoup3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup3","debian":"https://tracker.debian.org/pkg/libsoup3","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15713","published":"2026-07-14T20:16:00","updated_at":"2026-07-16T10:53:55.672417+00:00","description":"\nA vulnerability was found in libsoup's HTTP/2 protocol implementation. The\nlibrary fails to correctly release memory context blocks under specific\nstream termination conditions, such as when an HTTP/2 connection encounters\nwindow exhaustion or explicit stream resets. A remote, unauthenticated\nattacker acting as a malicious network peer can trick the connection engine\ninto allocating stream states that are subsequently leaked during cleanup.\nOver a sustained period, this flaw allows the remote attacker to consume\nthe system's heap allocations incrementally, triggering a denial of service\n(DoS) through an ultimate Out-of-Memory (OOM) application crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15713","https://access.redhat.com/security/cve/CVE-2026-15713","https://bugzilla.redhat.com/show_bug.cgi?id=2499941","https://gitlab.gnome.org/GNOME/libsoup/-/work_items/541"],"bugs":[""],"patches":{"libsoup3":[]},"tags":{},"packages":[{"name":"libsoup3","source":"https://ubuntu.com/security/cve?package=libsoup3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup3","debian":"https://tracker.debian.org/pkg/libsoup3","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15711","published":"2026-07-14T20:16:00","updated_at":"2026-07-16T10:53:55.672417+00:00","description":"\nA vulnerability was found in libsoup's WebSocket frame parsing\nimplementation. The library fails to validate length rules specified in RFC\n6455 ยง5.5, which mandates that all WebSocket control frames (e.g., PING,\nPONG, CLOSE) contain a payload of 125 bytes or less. A remote,\nunauthenticated attacker can exploit this by sending a non-compliant,\noversized control frame. Because the parser handles this protocol violation\nimproperly instead of throwing an immediate connection termination error,\nit triggers a internal processing crash, resulting in a remote denial of\nservice (DoS) for applications utilizing libsoup WebSockets.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15711","https://access.redhat.com/security/cve/CVE-2026-15711","https://bugzilla.redhat.com/show_bug.cgi?id=2499924","https://gitlab.gnome.org/GNOME/libsoup/-/issues/515"],"bugs":[""],"patches":{"libsoup2.4":[],"libsoup3":[]},"tags":{},"packages":[{"name":"libsoup2.4","source":"https://ubuntu.com/security/cve?package=libsoup2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup2.4","debian":"https://tracker.debian.org/pkg/libsoup2.4","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libsoup3","source":"https://ubuntu.com/security/cve?package=libsoup3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup3","debian":"https://tracker.debian.org/pkg/libsoup3","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15709","published":"2026-07-14T20:16:00","updated_at":"2026-07-16T10:53:55.672417+00:00","description":"\nA flaw was found in libsoup's WebSocket implementation when using the\npermessage-deflate extension. The extension's decompression loop\n(inflate()) processes data in chunks without enforcing an upper boundary\nlimit on the output buffer size. While libsoup limits the incoming\ncompressed frame size via max_incoming_payload_size, it fails to track or\nlimit memory allocation during decompression. A separate check for\ndecompressed size (max_total_message_size) exists but executes only after\ninflation is complete, and it is entirely disabled by default for client\nconnections. A remote, unauthenticated attacker can exploit this by sending\na small, highly compressed payload (a decompression bomb), causing\nunbounded memory allocation that triggers an Out-of-Memory (OOM) crash and\na Denial of Service (DoS).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15709","https://access.redhat.com/security/cve/CVE-2026-15709","https://bugzilla.redhat.com/show_bug.cgi?id=2499922","https://gitlab.gnome.org/GNOME/libsoup/-/issues/511"],"bugs":[""],"patches":{"libsoup2.4":[],"libsoup3":[]},"tags":{},"packages":[{"name":"libsoup2.4","source":"https://ubuntu.com/security/cve?package=libsoup2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup2.4","debian":"https://tracker.debian.org/pkg/libsoup2.4","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libsoup3","source":"https://ubuntu.com/security/cve?package=libsoup3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup3","debian":"https://tracker.debian.org/pkg/libsoup3","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47767","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:24:08.792657+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and\n8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET),\nbut parse_str() and the web SAPI can disagree, allowing a crafted query\nstring to leave $_GET empty while $_SERVER['argv'] still carries\nattacker-controlled --env or --no-debug flags that change APP_ENV or\nAPP_DEBUG. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and\n8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47767","https://github.com/symfony/symfony/commit/3228c3806ee511008bea19a95084d460b17e5d25","https://github.com/symfony/symfony/releases/tag/v5.4.52","https://github.com/symfony/symfony/releases/tag/v6.4.40","https://github.com/symfony/symfony/releases/tag/v7.4.12","https://github.com/symfony/symfony/releases/tag/v8.0.12","https://github.com/symfony/symfony/security/advisories/GHSA-fqc7-9xjw-jrh3"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47304","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:28:44.187250+00:00","description":"\nImproper verification of cryptographic signature in .NET allows an\nunauthorized attacker to bypass a security feature over a network.","ubuntu_description":"","notes":[{"author":"iconstantin","note":".NET 7 is end of life upstream."},{"author":"mdeslaur","note":"Marking .NET 6 as deferred until information is available to\ndetermine if it is impacted."}],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47304","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47304","https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-july-2026-servicing-updates","https://github.com/dotnet/announcements/issues/412","https://ubuntu.com/security/notices/USN-8553-1"],"bugs":[""],"patches":{"dotnet6":[],"dotnet7":[],"dotnet8":[],"dotnet9":[],"dotnet10":[]},"tags":{},"packages":[{"name":"dotnet6","source":"https://ubuntu.com/security/cve?package=dotnet6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet6","debian":"https://tracker.debian.org/pkg/dotnet6","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet7","source":"https://ubuntu.com/security/cve?package=dotnet7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet7","debian":"https://tracker.debian.org/pkg/dotnet7","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet8","source":"https://ubuntu.com/security/cve?package=dotnet8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet8","debian":"https://tracker.debian.org/pkg/dotnet8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"8.0.129-8.0.29-0ubuntu1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.0.129-8.0.29-0ubuntu1~24.04.1","component":null,"pocket":"security"}]},{"name":"dotnet9","source":"https://ubuntu.com/security/cve?package=dotnet9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet9","debian":"https://tracker.debian.org/pkg/dotnet9","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet10","source":"https://ubuntu.com/security/cve?package=dotnet10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet10","debian":"https://tracker.debian.org/pkg/dotnet10","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"10.0.110-10.0.10-0ubuntu1~24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"10.0.110-10.0.10-0ubuntu1~26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8553-1"],"notices":[{"id":"USN-8553-1","title":".NET vulnerabilities","summary":"Several security issues were fixed in .NET.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-15T17:13:59.965059","description":"Artur Stetsko discovered that the .NET did not properly validate\nauthentication data. An attacker could possibly use this issue to elevate\nprivileges. (CVE-2026-47300)\n\nLevi Broderick discovered that .NET did not properly handle XML encryption\nduring parsing. An attacker could possibly use this issue to consume\nexcessive resources, resulting in a denial of service. (CVE-2026-47302)\n\nPham Quang Minh discovered that .NET did not properly parse\nauthentication data. An attacker could possibly use this issue to bypass\nauthentication and elevate privileges. (CVE-2026-47303)\n\nLevi Broderick discovered that .NET did not properly verify cryptographic\nsignatures during XML encryption. An attacker could possibly use this issue\nto bypass security features over a network and access encrypted data.\n(CVE-2026-47304)\n\nIt was discovered that .NET did not properly validate input during TLS\nhandshakes. An attacker could possibly use this issue to cause .NET to\ncrash, resulting in a denial of service. (CVE-2026-50524)\n\nLevi Broderick discovered that .NET did not properly handle resource\nallocation during XML encryption. An attacker could possibly use this issue\nto consume excessive resources, resulting in a denial of service.\n(CVE-2026-50525)\n\nSiwei Li discovered that .NET did not properly handle link resolution\nbefore file access during the container image build process. A local\nattacker could possibly use this issue to inject resources that could be\nincorporated into container images built by other users on the same\nmachine. (CVE-2026-50526)\n\nLevi Broderick discovered that .NET did not properly handle memory while\nperforming XML encryption. An attacker could possibly use this issue to\ncause .NET to crash, resulting in a denial of service. (CVE-2026-50527)\n\nHenrique Pereira discovered that .NET did not properly handle\nauthorization checks during TLS/SSL connections. An attacker could\npossibly use this issue to bypass authorization checks during secure\ncommunications. (CVE-2026-50528)\n\nIt was discovered that .NET did not properly handle resource allocation\nduring XML encryption. An attacker could possibly use this issue to\nconsume excessive resources, resulting in a denial of service.\n(CVE-2026-50648)\n\nMiha Zupan discovered that .NET did not properly limit resource\nallocation when handling HTTP/2 requests. An attacker could possibly use\nthis issue to consume excessive resources, resulting in a denial of\nservice. (CVE-2026-50651)\n\nIt was discovered that the .NET SMTP client did not properly handle the\nencoding or escaping of output. An attacker could possibly use this issue\nto spoof messages during message routing. (CVE-2026-50659)\n\nIt was discovered that .NET did not properly validate resource types when\nparsing X.509 certificates. An attacker could possibly use this issue to\ncause .NET to crash, resulting in a denial of service. (CVE-2026-57108)","is_hidden":false,"release_packages":{"jammy":[{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~22.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"}],"noble":[{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"}],"resolute":[{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~26.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-57108","CVE-2026-50659","CVE-2026-47304","CVE-2026-50527","CVE-2026-50648","CVE-2026-50651","CVE-2026-47300","CVE-2026-47303","CVE-2026-50525","CVE-2026-50526","CVE-2026-50528","CVE-2026-50524","CVE-2026-47302"]}]},{"id":"CVE-2026-47303","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:28:44.187250+00:00","description":"\nAuthentication bypass by assumed-immutable data in ASP.NET Core allows an\nauthorized attacker to elevate privileges over a network.","ubuntu_description":"","notes":[{"author":"iconstantin","note":".NET 7 is end of life upstream."},{"author":"mdeslaur","note":"Marking .NET 6 as deferred until information is available to\ndetermine if it is impacted."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47303","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47303","https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-july-2026-servicing-updates","https://github.com/dotnet/announcements/issues/411","https://ubuntu.com/security/notices/USN-8553-1"],"bugs":[""],"patches":{"dotnet6":[],"dotnet7":[],"dotnet8":[],"dotnet9":[],"dotnet10":[]},"tags":{},"packages":[{"name":"dotnet6","source":"https://ubuntu.com/security/cve?package=dotnet6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet6","debian":"https://tracker.debian.org/pkg/dotnet6","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet7","source":"https://ubuntu.com/security/cve?package=dotnet7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet7","debian":"https://tracker.debian.org/pkg/dotnet7","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet8","source":"https://ubuntu.com/security/cve?package=dotnet8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet8","debian":"https://tracker.debian.org/pkg/dotnet8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"8.0.129-8.0.29-0ubuntu1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.0.129-8.0.29-0ubuntu1~24.04.1","component":null,"pocket":"security"}]},{"name":"dotnet9","source":"https://ubuntu.com/security/cve?package=dotnet9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet9","debian":"https://tracker.debian.org/pkg/dotnet9","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet10","source":"https://ubuntu.com/security/cve?package=dotnet10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet10","debian":"https://tracker.debian.org/pkg/dotnet10","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"10.0.110-10.0.10-0ubuntu1~24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"10.0.110-10.0.10-0ubuntu1~26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8553-1"],"notices":[{"id":"USN-8553-1","title":".NET vulnerabilities","summary":"Several security issues were fixed in .NET.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-15T17:13:59.965059","description":"Artur Stetsko discovered that the .NET did not properly validate\nauthentication data. An attacker could possibly use this issue to elevate\nprivileges. (CVE-2026-47300)\n\nLevi Broderick discovered that .NET did not properly handle XML encryption\nduring parsing. An attacker could possibly use this issue to consume\nexcessive resources, resulting in a denial of service. (CVE-2026-47302)\n\nPham Quang Minh discovered that .NET did not properly parse\nauthentication data. An attacker could possibly use this issue to bypass\nauthentication and elevate privileges. (CVE-2026-47303)\n\nLevi Broderick discovered that .NET did not properly verify cryptographic\nsignatures during XML encryption. An attacker could possibly use this issue\nto bypass security features over a network and access encrypted data.\n(CVE-2026-47304)\n\nIt was discovered that .NET did not properly validate input during TLS\nhandshakes. An attacker could possibly use this issue to cause .NET to\ncrash, resulting in a denial of service. (CVE-2026-50524)\n\nLevi Broderick discovered that .NET did not properly handle resource\nallocation during XML encryption. An attacker could possibly use this issue\nto consume excessive resources, resulting in a denial of service.\n(CVE-2026-50525)\n\nSiwei Li discovered that .NET did not properly handle link resolution\nbefore file access during the container image build process. A local\nattacker could possibly use this issue to inject resources that could be\nincorporated into container images built by other users on the same\nmachine. (CVE-2026-50526)\n\nLevi Broderick discovered that .NET did not properly handle memory while\nperforming XML encryption. An attacker could possibly use this issue to\ncause .NET to crash, resulting in a denial of service. (CVE-2026-50527)\n\nHenrique Pereira discovered that .NET did not properly handle\nauthorization checks during TLS/SSL connections. An attacker could\npossibly use this issue to bypass authorization checks during secure\ncommunications. (CVE-2026-50528)\n\nIt was discovered that .NET did not properly handle resource allocation\nduring XML encryption. An attacker could possibly use this issue to\nconsume excessive resources, resulting in a denial of service.\n(CVE-2026-50648)\n\nMiha Zupan discovered that .NET did not properly limit resource\nallocation when handling HTTP/2 requests. An attacker could possibly use\nthis issue to consume excessive resources, resulting in a denial of\nservice. (CVE-2026-50651)\n\nIt was discovered that the .NET SMTP client did not properly handle the\nencoding or escaping of output. An attacker could possibly use this issue\nto spoof messages during message routing. (CVE-2026-50659)\n\nIt was discovered that .NET did not properly validate resource types when\nparsing X.509 certificates. An attacker could possibly use this issue to\ncause .NET to crash, resulting in a denial of service. (CVE-2026-57108)","is_hidden":false,"release_packages":{"jammy":[{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~22.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"}],"noble":[{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"}],"resolute":[{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~26.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-57108","CVE-2026-50659","CVE-2026-47304","CVE-2026-50527","CVE-2026-50648","CVE-2026-50651","CVE-2026-47300","CVE-2026-47303","CVE-2026-50525","CVE-2026-50526","CVE-2026-50528","CVE-2026-50524","CVE-2026-47302"]}]},{"id":"CVE-2026-47302","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:28:44.187250+00:00","description":"\nAllocation of resources without limits or throttling in .NET allows an\nunauthorized attacker to deny service over a network.","ubuntu_description":"","notes":[{"author":"iconstantin","note":".NET 7 is end of life upstream."},{"author":"mdeslaur","note":"Marking .NET 6 as deferred until information is available to\ndetermine if it is impacted."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47302","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47302","https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-july-2026-servicing-updates","https://github.com/dotnet/announcements/issues/410","https://ubuntu.com/security/notices/USN-8553-1"],"bugs":[""],"patches":{"dotnet6":[],"dotnet7":[],"dotnet8":[],"dotnet9":[],"dotnet10":[]},"tags":{},"packages":[{"name":"dotnet6","source":"https://ubuntu.com/security/cve?package=dotnet6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet6","debian":"https://tracker.debian.org/pkg/dotnet6","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet7","source":"https://ubuntu.com/security/cve?package=dotnet7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet7","debian":"https://tracker.debian.org/pkg/dotnet7","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet8","source":"https://ubuntu.com/security/cve?package=dotnet8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet8","debian":"https://tracker.debian.org/pkg/dotnet8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"8.0.129-8.0.29-0ubuntu1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.0.129-8.0.29-0ubuntu1~24.04.1","component":null,"pocket":"security"}]},{"name":"dotnet9","source":"https://ubuntu.com/security/cve?package=dotnet9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet9","debian":"https://tracker.debian.org/pkg/dotnet9","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet10","source":"https://ubuntu.com/security/cve?package=dotnet10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet10","debian":"https://tracker.debian.org/pkg/dotnet10","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"10.0.110-10.0.10-0ubuntu1~24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"10.0.110-10.0.10-0ubuntu1~26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8553-1"],"notices":[{"id":"USN-8553-1","title":".NET vulnerabilities","summary":"Several security issues were fixed in .NET.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-15T17:13:59.965059","description":"Artur Stetsko discovered that the .NET did not properly validate\nauthentication data. An attacker could possibly use this issue to elevate\nprivileges. (CVE-2026-47300)\n\nLevi Broderick discovered that .NET did not properly handle XML encryption\nduring parsing. An attacker could possibly use this issue to consume\nexcessive resources, resulting in a denial of service. (CVE-2026-47302)\n\nPham Quang Minh discovered that .NET did not properly parse\nauthentication data. An attacker could possibly use this issue to bypass\nauthentication and elevate privileges. (CVE-2026-47303)\n\nLevi Broderick discovered that .NET did not properly verify cryptographic\nsignatures during XML encryption. An attacker could possibly use this issue\nto bypass security features over a network and access encrypted data.\n(CVE-2026-47304)\n\nIt was discovered that .NET did not properly validate input during TLS\nhandshakes. An attacker could possibly use this issue to cause .NET to\ncrash, resulting in a denial of service. (CVE-2026-50524)\n\nLevi Broderick discovered that .NET did not properly handle resource\nallocation during XML encryption. An attacker could possibly use this issue\nto consume excessive resources, resulting in a denial of service.\n(CVE-2026-50525)\n\nSiwei Li discovered that .NET did not properly handle link resolution\nbefore file access during the container image build process. A local\nattacker could possibly use this issue to inject resources that could be\nincorporated into container images built by other users on the same\nmachine. (CVE-2026-50526)\n\nLevi Broderick discovered that .NET did not properly handle memory while\nperforming XML encryption. An attacker could possibly use this issue to\ncause .NET to crash, resulting in a denial of service. (CVE-2026-50527)\n\nHenrique Pereira discovered that .NET did not properly handle\nauthorization checks during TLS/SSL connections. An attacker could\npossibly use this issue to bypass authorization checks during secure\ncommunications. (CVE-2026-50528)\n\nIt was discovered that .NET did not properly handle resource allocation\nduring XML encryption. An attacker could possibly use this issue to\nconsume excessive resources, resulting in a denial of service.\n(CVE-2026-50648)\n\nMiha Zupan discovered that .NET did not properly limit resource\nallocation when handling HTTP/2 requests. An attacker could possibly use\nthis issue to consume excessive resources, resulting in a denial of\nservice. (CVE-2026-50651)\n\nIt was discovered that the .NET SMTP client did not properly handle the\nencoding or escaping of output. An attacker could possibly use this issue\nto spoof messages during message routing. (CVE-2026-50659)\n\nIt was discovered that .NET did not properly validate resource types when\nparsing X.509 certificates. An attacker could possibly use this issue to\ncause .NET to crash, resulting in a denial of service. (CVE-2026-57108)","is_hidden":false,"release_packages":{"jammy":[{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~22.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"}],"noble":[{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"}],"resolute":[{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~26.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-57108","CVE-2026-50659","CVE-2026-47304","CVE-2026-50527","CVE-2026-50648","CVE-2026-50651","CVE-2026-47300","CVE-2026-47303","CVE-2026-50525","CVE-2026-50526","CVE-2026-50528","CVE-2026-50524","CVE-2026-47302"]}]},{"id":"CVE-2026-47300","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:28:44.187250+00:00","description":"\nIncorrect implementation of authentication algorithm in ASP.NET Core allows\nan authorized attacker to elevate privileges over a network.","ubuntu_description":"","notes":[{"author":"iconstantin","note":".NET 7 is end of life upstream."},{"author":"mdeslaur","note":"Marking .NET 6 as deferred until information is available to\ndetermine if it is impacted."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47300","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47300","https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-july-2026-servicing-updates","https://github.com/dotnet/announcements/issues/409","https://ubuntu.com/security/notices/USN-8553-1"],"bugs":[""],"patches":{"dotnet6":[],"dotnet7":[],"dotnet8":[],"dotnet9":[],"dotnet10":[]},"tags":{},"packages":[{"name":"dotnet6","source":"https://ubuntu.com/security/cve?package=dotnet6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet6","debian":"https://tracker.debian.org/pkg/dotnet6","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet7","source":"https://ubuntu.com/security/cve?package=dotnet7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet7","debian":"https://tracker.debian.org/pkg/dotnet7","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet8","source":"https://ubuntu.com/security/cve?package=dotnet8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet8","debian":"https://tracker.debian.org/pkg/dotnet8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"8.0.129-8.0.29-0ubuntu1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"8.0.129-8.0.29-0ubuntu1~24.04.1","component":null,"pocket":"security"}]},{"name":"dotnet9","source":"https://ubuntu.com/security/cve?package=dotnet9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet9","debian":"https://tracker.debian.org/pkg/dotnet9","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dotnet10","source":"https://ubuntu.com/security/cve?package=dotnet10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dotnet10","debian":"https://tracker.debian.org/pkg/dotnet10","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"10.0.110-10.0.10-0ubuntu1~24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"10.0.110-10.0.10-0ubuntu1~26.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8553-1"],"notices":[{"id":"USN-8553-1","title":".NET vulnerabilities","summary":"Several security issues were fixed in .NET.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-15T17:13:59.965059","description":"Artur Stetsko discovered that the .NET did not properly validate\nauthentication data. An attacker could possibly use this issue to elevate\nprivileges. (CVE-2026-47300)\n\nLevi Broderick discovered that .NET did not properly handle XML encryption\nduring parsing. An attacker could possibly use this issue to consume\nexcessive resources, resulting in a denial of service. (CVE-2026-47302)\n\nPham Quang Minh discovered that .NET did not properly parse\nauthentication data. An attacker could possibly use this issue to bypass\nauthentication and elevate privileges. (CVE-2026-47303)\n\nLevi Broderick discovered that .NET did not properly verify cryptographic\nsignatures during XML encryption. An attacker could possibly use this issue\nto bypass security features over a network and access encrypted data.\n(CVE-2026-47304)\n\nIt was discovered that .NET did not properly validate input during TLS\nhandshakes. An attacker could possibly use this issue to cause .NET to\ncrash, resulting in a denial of service. (CVE-2026-50524)\n\nLevi Broderick discovered that .NET did not properly handle resource\nallocation during XML encryption. An attacker could possibly use this issue\nto consume excessive resources, resulting in a denial of service.\n(CVE-2026-50525)\n\nSiwei Li discovered that .NET did not properly handle link resolution\nbefore file access during the container image build process. A local\nattacker could possibly use this issue to inject resources that could be\nincorporated into container images built by other users on the same\nmachine. (CVE-2026-50526)\n\nLevi Broderick discovered that .NET did not properly handle memory while\nperforming XML encryption. An attacker could possibly use this issue to\ncause .NET to crash, resulting in a denial of service. (CVE-2026-50527)\n\nHenrique Pereira discovered that .NET did not properly handle\nauthorization checks during TLS/SSL connections. An attacker could\npossibly use this issue to bypass authorization checks during secure\ncommunications. (CVE-2026-50528)\n\nIt was discovered that .NET did not properly handle resource allocation\nduring XML encryption. An attacker could possibly use this issue to\nconsume excessive resources, resulting in a denial of service.\n(CVE-2026-50648)\n\nMiha Zupan discovered that .NET did not properly limit resource\nallocation when handling HTTP/2 requests. An attacker could possibly use\nthis issue to consume excessive resources, resulting in a denial of\nservice. (CVE-2026-50651)\n\nIt was discovered that the .NET SMTP client did not properly handle the\nencoding or escaping of output. An attacker could possibly use this issue\nto spoof messages during message routing. (CVE-2026-50659)\n\nIt was discovered that .NET did not properly validate resource types when\nparsing X.509 certificates. An attacker could possibly use this issue to\ncause .NET to crash, resulting in a denial of service. (CVE-2026-57108)","is_hidden":false,"release_packages":{"jammy":[{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~22.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.129-0ubuntu1~22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~22.04.1","pocket":"security"}],"noble":[{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~24.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-host-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-hostfxr-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-8.0-source-built-artifacts","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-8.0","version":"8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.110-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet-templates-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~24.04.1","pocket":"security"},{"name":"dotnet8","version":"8.0.129-8.0.29-0ubuntu1~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"},{"name":"netstandard-targeting-pack-2.1-8.0","version":"8.0.129-0ubuntu1~24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet8","version_link":"https://launchpad.net/ubuntu/+source/dotnet8/8.0.129-8.0.29-0ubuntu1~24.04.1","pocket":"security"}],"resolute":[{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~26.04.1","description":".NET CLI tools and runtime","is_source":true},{"name":"aspnetcore-runtime-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"aspnetcore-targeting-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-apphost-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-host-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-hostfxr-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-runtime-dbg-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-10.0-source-built-artifacts","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-aot-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-sdk-dbg-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-targeting-pack-10.0","version":"10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet-templates-10.0","version":"10.0.110-0ubuntu1~26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"},{"name":"dotnet10","version":"10.0.110-10.0.10-0ubuntu1~26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/dotnet10","version_link":"https://launchpad.net/ubuntu/+source/dotnet10/10.0.110-10.0.10-0ubuntu1~26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-57108","CVE-2026-50659","CVE-2026-47304","CVE-2026-50527","CVE-2026-50648","CVE-2026-50651","CVE-2026-47300","CVE-2026-47303","CVE-2026-50525","CVE-2026-50526","CVE-2026-50528","CVE-2026-50524","CVE-2026-47302"]}]},{"id":"CVE-2026-45755","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:23:47.812290+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 7.4.12 and 8.0.12,\nMailtrapRequestParser::doParse() received the configured webhook secret but\nignored the X-Mt-Signature HMAC header, allowing unauthenticated POST\nrequests to inject forged Mailtrap delivery, bounce, open, click, or spam\nevents. This issue is fixed in versions 7.4.12 and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45755","https://symfony.com/blog/cve-2026-45755-mailtrap-mailer-webhook-parser-never-verifies-the-x-mt-signature-hmac-unauthenticated-webhook-event-injection"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45754","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:24:22.972425+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet\nmailer bridge and LOX24 notifier bridge webhook parsers received configured\nwebhook secrets but did not verify them, allowing unauthenticated POST\nrequests to inject forged Mailjet and LOX24 event payloads. This issue is\nfixed in versions 6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45754","https://symfony.com/blog/cve-2026-45754-mailjet-and-lox24-webhook-parsers-never-verify-the-configured-secret-unauthenticated-event-injection"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45753","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:24:08.792657+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12,\nUrlAttributeSanitizer::getSupportedAttributes() omits URL-valued attributes\nincluding action, formaction, poster, and cite, so configurations that\nadmit those attributes can leave javascript: URIs unsanitized and enable\nXSS when the resulting HTML is rendered or a victim submits a form or\nclicks a button. This issue is fixed in versions 6.4.40, 7.4.12, and\n8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45753","https://symfony.com/blog/cve-2026-45753-htmlsanitizer-urlattributesanitizer-omits-action-formaction-poster-cite-javascript-uri-survives-sanitization-xss"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45305","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:23:47.812290+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12,\nSymfony\\Component\\Yaml\\Parser::cleanup() used regular expressions with\noverlapping quantifiers for YAML directive, comment, and document marker\ncleanup, allowing crafted input to make parsing hang for an arbitrarily\nlong time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and\n8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45305","https://symfony.com/blog/cve-2026-45305-yaml-parser-redos-via-catastrophic-backtracking-in-parser-cleanup-regex"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45304","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:24:08.792657+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12,\nSymfony\\Component\\Yaml\\Parser resolved YAML collection aliases recursively,\nallowing a small untrusted YAML input to expand into a multi-gigabyte\nstructure and exhaust memory. This issue is fixed in versions 5.4.52,\n6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45304","https://symfony.com/blog/cve-2026-45304-yaml-parser-exponential-memory-allocation-via-recursive-collection-alias-expansion-billion-laughs"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45133","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:23:47.812290+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when\nthe parser is exposed to attacker-controlled input, deeply nested mappings\nor sequences cause both the block-level (Parser::parseBlock()) and inline\n(Inline::parseSequence() / Inline::parseMapping()) parsers to recurse\nwithout a depth limit. A crafted document exhausts the PHP stack and\ncrashes the worker. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12,\nand 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45133","https://symfony.com/blog/cve-2026-45133-yaml-parser-stack-exhaustion-via-unbounded-recursion-in-nested-blocks-sequences-and-mappings"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45075","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:24:08.792657+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped\n#[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can\nbe configured for GET only, but Symfony routes HEAD requests to the GET\nhandler while the attribute check is skipped, allowing protected\ncontrollers to execute and leak headers or perform side effects. This issue\nis fixed in versions 7.4.12 and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45075","https://symfony.com/blog/cve-2026-45075-head-request-bypasses-methods-get-filter-in-isgranted-issignaturevalid-iscsrftokenvalid"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45073","published":"2026-07-14T19:17:00","updated_at":"2026-07-17T19:24:22.972425+00:00","description":"\nSymfony is a PHP framework for web and console applications and a set of\nreusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12,\nPdoAdapter::doClear() builds a DELETE statement using a namespace derived\nfrom the caller-supplied $prefix without binding or escaping it, allowing a\ncaller able to influence $prefix to break out of the LIKE literal and alter\nquery semantics or deletion scope. This issue is fixed in versions 5.4.52,\n6.4.40, 7.4.12, and 8.0.12.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45073","https://symfony.com/blog/cve-2026-45073-sql-injection-in-pdoadapter-doclear-via-unsanitized-prefix"],"bugs":[""],"patches":{"symfony":[]},"tags":{},"packages":[{"name":"symfony","source":"https://ubuntu.com/security/cve?package=symfony","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=symfony","debian":"https://tracker.debian.org/pkg/symfony","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":7680,"limit":20,"total_results":79316}