Bitnami package
dotnet
pkg:bitnami/dotnet
Vulnerabilities (121)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-50525 | Hig | 7.5 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-50524 | Hig | 7.5 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-47304 | Hig | 8.1 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2026-47303 | Hig | 8.8 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-47302 | Hig | 7.5 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-47300 | Hig | 8.8 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network. | |
| CVE-2026-57108 | Hig | 7.5 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-56170 | Hig | 7.5 | >= 8.0.0, < 8.0.29 | 8.0.29 | Jul 14, 2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-45591 | Hig | 7.5 | >= 8.0.0, < 8.0.28 | 8.0.28 | Jun 9, 2026 | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-45491 | Med | 6.2 | >= 8.0.0, < 8.0.28 | 8.0.28 | Jun 9, 2026 | Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally. | |
| CVE-2026-45490 | Hig | 7.8 | >= 8.0.0, < 8.0.28 | 8.0.28 | Jun 9, 2026 | Improper authorization in .NET allows an authorized attacker to elevate privileges locally. | |
| CVE-2026-42899 | Hig | 7.5 | >= 8.0.0, < 8.0.27 | 8.0.27 | May 12, 2026 | Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-35433 | Hig | 7.3 | >= 8.0.0, < 8.0.27 | 8.0.27 | May 12, 2026 | Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | |
| CVE-2026-32177 | Hig | 7.3 | >= 8.0.0, < 8.0.27 | 8.0.27 | May 12, 2026 | Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. | |
| CVE-2026-32175 | Med | 4.3 | >= 8.0.0, < 8.0.27 | 8.0.27 | May 12, 2026 | A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited c | |
| CVE-2026-33116 | Hig | 7.5 | >= 8.0.0, < 8.0.26 | 8.0.26 | Apr 14, 2026 | Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-32203 | Hig | 7.5 | >= 8.0.0, < 8.0.26 | 8.0.26 | Apr 14, 2026 | Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-32178 | Hig | 7.5 | >= 8.0.0, < 8.0.26 | 8.0.26 | Apr 14, 2026 | Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2026-26171 | Hig | 7.5 | >= 8.0.0, < 8.0.26 | 8.0.26 | Apr 14, 2026 | Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-25667 | Hig | 7.5 | >= 8.0.0, < 8.0.22 | 8.0.22 | Mar 19, 2026 | ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing. |
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.29fixed 8.0.29
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.28fixed 8.0.28
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.28fixed 8.0.28
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
- affected >= 8.0.0, < 8.0.28fixed 8.0.28
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
- affected >= 8.0.0, < 8.0.27fixed 8.0.27
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.27fixed 8.0.27
Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally.
- affected >= 8.0.0, < 8.0.27fixed 8.0.27
Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally.
- affected >= 8.0.0, < 8.0.27fixed 8.0.27
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited c
- affected >= 8.0.0, < 8.0.26fixed 8.0.26
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.26fixed 8.0.26
Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.26fixed 8.0.26
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
- affected >= 8.0.0, < 8.0.26fixed 8.0.26
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.22fixed 8.0.22
ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing.
Page 2 of 7