Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ USN-8553-1 — dotnet10 (CVE-2026-47300 +12 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

dotnet8, dotnet10 vulnerabilities

Artur Stetsko discovered that the .NET did not properly validate

authentication data. An attacker could possibly use this issue to elevate

privileges. (CVE-2026-47300)

Levi Broderick discovered that .NET did not properly handle XML encryption

during parsing. An attacker could possibly use this issue to consume

excessive resources, resulting in a denial of service. (CVE-2026-47302)

Pham Quang Minh discovered that .NET did not properly parse

authentication data. An attacker could possibly use this issue to bypass

authentication and elevate privileges. (CVE-2026-47303)

Levi Broderick discovered that .NET did not properly verify cryptographic

signatures during XML encryption. An attacker could possibly use this issue

to bypass security features over a network and access encrypted data.

(CVE-2026-47304)

It was discovered that .NET did not properly validate input during TLS

handshakes. An attacker could possibly use this issue to cause .NET to

crash, resulting in a denial of service. (CVE-2026-50524)

Levi Broderick discovered that .NET did not properly handle resource

allocation during XML encryption. An attacker could possibly use this issue

to consume excessive resources, resulting in a denial of service.

(CVE-2026-50525)

Siwei Li discovered that .NET did not properly handle link resolution

before file access during the container image build process. A local

attacker could possibly use this issue to inject resources that could be

incorporated into container images built by other users on the same

machine. (CVE-2026-50526)

Levi Broderick discovered that .NET did not properly handle memory while

performing XML encryption. An attacker could possibly use this issue to

cause .NET to crash, resulting in a denial of service. (CVE-2026-50527)

Henrique Pereira discovered that .NET did not properly handle

authorization checks during TLS/SSL connections. An attacker could

possibly use this issue to bypass authorization checks during secure

communications. (CVE-2026-50528)

It was discovered that .NET did not properly handle resource allocation

during XML encryption. An attacker could possibly use this issue to

consume excessive resources, resulting in a denial of service.

(CVE-2026-50648)

Miha Zupan discovered that .NET did not properly limit resource

allocation when handling HTTP/2 requests. An attacker could possibly use

this issue to consume excessive resources, resulting in a denial of

service. (CVE-2026-50651)

It was discovered that the .NET SMTP client did not properly handle the

encoding or escaping of output. An attacker could possibly use this issue

to spoof messages during message routing. (CVE-2026-50659)

It was discovered that .NET did not properly validate resource types when

parsing X.509 certificates. An attacker could possibly use this issue to

cause .NET to crash, resulting in a denial of service. (CVE-2026-57108)

Affected software

USN-8553-1 is recorded against 2 packages.

  • dotnet10 (fixed in 10.0.110-10.0.10-0ubuntu1~26.04.1)
  • dotnet8 (fixed in 8.0.129-8.0.29-0ubuntu1~24.04.1)

Timeline and source

Published on 15 July 2026 and last revised on 27 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

ubuntu.com (Advisory)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)

Other advisories for this package

dotnet10 has other advisories on record. If you are patching this one, these are worth checking on the same host:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-07-15
Updated 2026-08-20
Modified 2026-07-27
Fix URL N/A

Affected Packages

Software From version Fixed in
dotnet10 10.0.110-10.0.10-0ubuntu1~26.04.1
dotnet8 8.0.129-8.0.29-0ubuntu1~24.04.1

Free Vulnerability Check

Is your site affected by USN-8553-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against USN-8553-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesUbuntuUbuntu Undated