apk package
wolfi/dotnet-8-sdk
pkg:apk/wolfi/dotnet-8-sdk
Vulnerabilities (10)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-50648 | Hig | 7.5 | < 8.0.129-r1 | 8.0.129-r1 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-50525 | Hig | 7.5 | < 8.0.129-r1 | 8.0.129-r1 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-47304 | Hig | 8.1 | < 8.0.129-r1 | 8.0.129-r1 | Jul 14, 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2026-47302 | Hig | 7.5 | < 8.0.129-r1 | 8.0.129-r1 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-33116 | Hig | 7.5 | < 8.0.126-r0 | 8.0.126-r0 | Apr 14, 2026 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-26171 | Hig | 7.5 | < 8.0.126-r0 | 8.0.126-r0 | Apr 14, 2026 | Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2025-55315 | Cri | 9.9 | < 8.0.121-r0 | 8.0.121-r0 | Oct 14, 2025 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | |
| CVE-2025-26646 | Hig | 8.0 | < 0 | 0 | May 13, 2025 | External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. | |
| CVE-2024-38095 | Hig | 7.5 | < 8.0.7-r0 | 8.0.7-r0 | Jul 9, 2024 | .NET and Visual Studio Denial of Service Vulnerability | |
| CVE-2024-30105 | Hig | 7.5 | < 8.0.7-r0 | 8.0.7-r0 | Jul 9, 2024 | .NET and Visual Studio Denial of Service Vulnerability |
- affected < 8.0.129-r1fixed 8.0.129-r1
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
- affected < 8.0.129-r1fixed 8.0.129-r1
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- affected < 8.0.129-r1fixed 8.0.129-r1
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
- affected < 8.0.129-r1fixed 8.0.129-r1
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- affected < 8.0.126-r0fixed 8.0.126-r0
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
- affected < 8.0.126-r0fixed 8.0.126-r0
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
- affected < 8.0.121-r0fixed 8.0.121-r0
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
- affected < 0fixed 0
External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network.
- affected < 8.0.7-r0fixed 8.0.7-r0
.NET and Visual Studio Denial of Service Vulnerability
- affected < 8.0.7-r0fixed 8.0.7-r0
.NET and Visual Studio Denial of Service Vulnerability