Known vulnerabilities in .NET 8.0.0

Vendor: Microsoft
Software: .NET
Version: 8.0.0
Software CPE: cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
Total vulnerabilities: 71
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting .NET version 8.0.0 .NET 8.0.0 is affected by 71 vulnerabilities: 14 high, 43 medium, 14 low Critical High Medium Low

Vulnerabilities (71)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU148055 - Heap-based Buffer Overflow
CVE-2026-71328
CWE-122 High
No
No
8.0.31, 9.0.20 09.09.2026 SB2026090910
SB20260914139
SB20260914140
and 5 more
#VU147767 - Heap-based Buffer Overflow
CVE-2026-69522
CWE-122 High
No
No
8.0.31, 9.0.20 08.09.2026 SB2026090910
SB20260914139
SB20260914140
and 5 more
#VU147695 - Heap-based Buffer Overflow
CVE-2026-69439
CWE-122 High
No
No
8.0.31, 9.0.20 08.09.2026 SB2026090910
SB20260914139
SB20260914140
and 5 more
#VU147576 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-69304
CWE-409 Medium
No
No
8.0.31, 9.0.20 08.09.2026 SB2026090910
SB20260914139
SB20260914140
and 5 more
#VU147478 - Origin Validation Error
CVE-2026-58649
CWE-346 Medium
No
No
8.0.130, 8.0.424, 9.0.120, 9.0.317 08.09.2026 SB2026090910
SB20260914139
SB20260914140
and 14 more
#VU142006 - Use After Free
CVE-2026-62898
CWE-416 Medium
No
No
8.0.30, 9.0.19 12.08.2026 SB20260812233
SB2026081416
SB2026081417
and 4 more
#VU141930 - Integer overflow
CVE-2026-62886
CWE-190 High
No
No
8.0.30, 9.0.19 12.08.2026 SB20260812233
SB2026081416
SB2026081417
and 4 more
#VU141923 - Out-of-bounds write
CVE-2026-62871
CWE-787 High
No
No
8.0.30, 9.0.19 12.08.2026 SB20260812233
SB2026081416
SB2026081417
and 4 more
#VU141876 - Integer overflow
CVE-2026-58641
CWE-190 High
No
No
8.0.30, 9.0.19 12.08.2026 SB20260812233
#VU141795 - Unchecked Return Value
CVE-2026-62909
CWE-252 Low
No
No
8.0.30, 9.0.19 12.08.2026 SB20260812233
SB2026081360
SB2026081364
and 11 more
#VU141793 - Inclusion of Functionality from Untrusted Control Sphere
CVE-2026-62902
CWE-829 Medium
No
No
8.0.30, 9.0.19 12.08.2026 SB20260812233
SB2026081416
SB2026081417
and 4 more
#VU141792 - Unchecked Input for Loop Condition
CVE-2026-62901
CWE-606 Medium
No
No
8.0.30, 9.0.19 12.08.2026 SB20260812233
SB2026081360
SB2026081364
and 11 more
#VU141791 - Improper Removal of Sensitive Information Before Storage or Transfer
CVE-2026-62900
CWE-212 Medium
No
No
8.0.30, 9.0.19 12.08.2026 SB20260812233
SB2026081360
SB2026081364
and 11 more
#VU141790 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-62899
CWE-444 Medium
No
No
8.0.30, 9.0.19 12.08.2026 SB20260812233
SB2026081360
SB2026081364
and 11 more
#VU141789 - Integer overflow
CVE-2026-62897
CWE-190 Medium
No
No
8.0.30, 9.0.19 12.08.2026 SB20260812233
SB2026081416
SB2026081417
and 4 more
#VU141498 - Out-of-bounds write
CVE-2026-70354
CWE-787 High
No
No
8.0.30, 9.0.19 11.08.2026 SB2026081155
SB2026081416
SB2026081417
and 4 more
#VU138139 - Type confusion
CVE-2026-57108
CWE-843 Medium
No
No
8.0.29, 9.0.18 17.07.2026 SB2026071706
SB20260721104
SB2026082404
and 1 more
#VU138088 - Improper Encoding or Escaping of Output
CVE-2026-50659
CWE-116 Low
No
No
8.0.29, 9.0.18 17.07.2026 SB2026071706
SB20260721104
SB2026082404
and 1 more
#VU138087 - Allocation of Resources Without Limits or Throttling
CVE-2026-50651
CWE-770 Medium
No
No
8.0.29, 9.0.18 17.07.2026 SB2026071706
SB20260721104
SB2026082404
and 1 more
#VU138080 - Stack-based buffer overflow
CVE-2026-50527
CWE-121 Medium
No
No
8.0.29, 9.0.18 17.07.2026 SB2026071706
SB20260721104
SB2026082404
and 1 more


Showing elements 1 - 20 out of 71