CVE-2026-32178Improper Neutralization of Special Elements in Microsoft Visual Studio 2022 Version 17.12

Severity
7.5HIGHNVD
EPSS
0.1%
top 83.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateApr 15

Description

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages17 packages

CVEListV5microsoft/net_8.08.08.0.26+1
CVEListV5microsoft/net_9.09.0.09.0.15
CVEListV5microsoft/net_10.010.0.010.0.6

🔴Vulnerability Details

3
VulDB
Microsoft .NET 2016/2017/2019/2022/2025 special element2026-04-14
GHSA
Microsoft Security Advisory CVE-2026-32178 – .NET Spoofing Vulnerability2026-04-14
CVEList
.NET Spoofing Vulnerability2026-04-14

📋Vendor Advisories

2
Ubuntu
.NET vulnerabilities2026-04-15
Red Hat
dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw2026-04-14

💬Community

4
Bugzilla
CVE-2026-32178 dotnet10.0: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw [fedora-all]2026-04-14
Bugzilla
CVE-2026-32178 dotnet9.0: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw [fedora-all]2026-04-14
Bugzilla
CVE-2026-32178 dotnet8.0: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw [fedora-all]2026-04-14
Bugzilla
CVE-2026-32178 dotnet: Dotnet: SMTP Command Injection and Header Injection via MailAddress parsing flaw2026-04-13
CVE-2026-32178 — Microsoft vulnerability | cvebase