VYPR
High severity7.5GHSA Advisory· Published Apr 14, 2026· Updated May 7, 2026

CVE-2026-32178

CVE-2026-32178

Description

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.NetCore.App.Runtime.linux-armNuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.linux-musl-armNuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.linux-arm64NuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.linux-musl-x64NuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.linux-musl-arm64NuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.linux-x64NuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.osx-arm64NuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.osx-x64NuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.win-armNuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.win-arm64NuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.win-x64NuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.win-x86NuGet
>= 10.0.0, < 10.0.610.0.6
Microsoft.NetCore.App.Runtime.linux-armNuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.linux-arm64NuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.linux-musl-armNuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.linux-musl-arm64NuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.linux-musl-x64NuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.linux-x64NuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.osx-arm64NuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.osx-x64NuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.win-armNuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.win-arm64NuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.win-x64NuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.win-x86NuGet
>= 9.0.0, < 9.0.159.0.15
Microsoft.NetCore.App.Runtime.linux-armNuGet
>= 8.0.0, < 8.0.268.0.26
Microsoft.NetCore.App.Runtime.linux-arm64NuGet
>= 8.0.0, < 8.0.268.0.26
Microsoft.NetCore.App.Runtime.linux-musl-armNuGet
>= 8.0.0, < 8.0.268.0.26
Microsoft.NetCore.App.Runtime.linux-musl-arm64NuGet
>= 8.0.0, < 8.0.268.0.26
Microsoft.NetCore.App.Runtime.linux-musl-x64NuGet
>= 8.0.0, < 8.0.268.0.26
Microsoft.NetCore.App.Runtime.linux-x64NuGet
>= 8.0.0, < 8.0.268.0.26
Microsoft.NetCore.App.Runtime.osx-arm64NuGet
>= 8.0.0, < 8.0.268.0.26
Microsoft.NetCore.App.Runtime.osx-x64NuGet
>= 8.0.0, < 8.0.268.0.26
Microsoft.NetCore.App.Runtime.win-armNuGet
>= 8.0.0, < 8.0.268.0.26
Microsoft.NetCore.App.Runtime.win-arm64NuGet
>= 8.0.0, < 8.0.268.0.26
Microsoft.NetCore.App.Runtime.win-x64NuGet
>= 8.0.0, < 8.0.268.0.26
Microsoft.NetCore.App.Runtime.win-x86NuGet
>= 8.0.0, < 8.0.268.0.26

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

50