High severityNVD Advisory· Published Feb 10, 2026· Updated Apr 10, 2026
.NET Spoofing Vulnerability
CVE-2026-21218
Description
Improper handling of missing special element in .NET allows an unauthorized attacker to perform spoofing over a network.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
System.Security.Cryptography.CoseNuGet | >= 8.0.0, < 8.0.2 | 8.0.2 |
System.Security.Cryptography.CoseNuGet | >= 9.0.0, < 9.0.13 | 9.0.13 |
System.Security.Cryptography.CoseNuGet | >= 10.0.0, < 10.0.3 | 10.0.3 |
Affected products
12- osv-coords9 versionspkg:apk/chainguard/dotnet-10pkg:apk/chainguard/dotnet-8pkg:apk/chainguard/dotnet-9pkg:apk/wolfi/dotnet-10pkg:apk/wolfi/dotnet-8pkg:apk/wolfi/dotnet-9pkg:bitnami/dotnetpkg:bitnami/dotnet-sdkpkg:nuget/system.security.cryptography.cose
< 10.0.103-r0+ 8 more
- (no CPE)range: < 10.0.103-r0
- (no CPE)range: < 8.0.124-r0
- (no CPE)range: < 9.0.114-r0
- (no CPE)range: < 10.0.103-r0
- (no CPE)range: < 8.0.124-r0
- (no CPE)range: < 9.0.114-r0
- (no CPE)range: >= 8.0.0, < 8.0.24
- (no CPE)range: >= 8.0.0, < 8.0.24
- (no CPE)range: >= 8.0.0, < 8.0.2
- Microsoft/.NET 10.0v5Range: 10.0.0
- Microsoft/.NET 8.0v5Range: 8.0.0
- Microsoft/.NET 9.0v5Range: 9.0.0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-qvhc-9v3j-5rfwghsaADVISORY
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21218ghsavendor-advisorypatchWEB
- nvd.nist.gov/vuln/detail/CVE-2026-21218ghsaADVISORY
- github.com/dotnet/runtime/security/advisories/GHSA-qvhc-9v3j-5rfwghsaWEB
News mentions
0No linked articles in our index yet.