VYPR
High severity7.5NVD Advisory· Published Aug 11, 2026· Updated Aug 14, 2026

CVE-2026-62901

CVE-2026-62901

Description

Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.NETCore.App.Runtime.win-arm64NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.NETCore.App.Runtime.win-x64NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.NETCore.App.Runtime.win-x86NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.NETCore.App.Runtime.linux-armNuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.NETCore.App.Runtime.linux-arm64NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.NETCore.App.Runtime.linux-musl-armNuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.NETCore.App.Runtime.linux-musl-arm64NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.NETCore.App.Runtime.linux-musl-x64NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.NETCore.App.Runtime.linux-x64NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.NETCore.App.Runtime.osx-arm64NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.NETCore.App.Runtime.osx-x64NuGet
>= 10.0.0, < 10.0.1110.0.11
Microsoft.NETCore.App.Runtime.win-arm64NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.NETCore.App.Runtime.win-x64NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.NETCore.App.Runtime.win-x86NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.NETCore.App.Runtime.linux-armNuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.NETCore.App.Runtime.linux-arm64NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.NETCore.App.Runtime.linux-musl-armNuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.NETCore.App.Runtime.linux-musl-arm64NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.NETCore.App.Runtime.linux-musl-x64NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.NETCore.App.Runtime.linux-x64NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.NETCore.App.Runtime.osx-arm64NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.NETCore.App.Runtime.osx-x64NuGet
>= 9.0.0, < 9.0.199.0.19
Microsoft.NETCore.App.Runtime.win-arm64NuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.NETCore.App.Runtime.win-x64NuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.NETCore.App.Runtime.win-x86NuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.NETCore.App.Runtime.linux-armNuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.NETCore.App.Runtime.linux-arm64NuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.NETCore.App.Runtime.linux-musl-armNuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.NETCore.App.Runtime.linux-musl-arm64NuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.NETCore.App.Runtime.linux-musl-x64NuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.NETCore.App.Runtime.linux-x64NuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.NETCore.App.Runtime.osx-arm64NuGet
>= 8.0.0, < 8.0.308.0.30
Microsoft.NETCore.App.Runtime.osx-x64NuGet
>= 8.0.0, < 8.0.308.0.30

Affected products

48

Patches

Vulnerability mechanics

References

5

News mentions

2