CVE-2026-62899
published 2026-08-11CVE-2026-62899: Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a…
PriorityP338medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.71%
51.0th percentile
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devspaces | udi-rhel9 | — | — |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 10.0.0 < 10.0.11 | 10.0.11 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 8.0.0 < 8.0.30 | 8.0.30 |
| microsoft | microsoft.netcore.app.runtime.linux-arm | >= 9.0.0 < 9.0.19 | 9.0.19 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 10.0.0 < 10.0.11 | 10.0.11 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 8.0.0 < 8.0.30 | 8.0.30 |
| microsoft | microsoft.netcore.app.runtime.linux-arm64 | >= 9.0.0 < 9.0.19 | 9.0.19 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 10.0.0 < 10.0.11 | 10.0.11 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 8.0.0 < 8.0.30 | 8.0.30 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm | >= 9.0.0 < 9.0.19 | 9.0.19 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 10.0.0 < 10.0.11 | 10.0.11 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 8.0.0 < 8.0.30 | 8.0.30 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-arm64 | >= 9.0.0 < 9.0.19 | 9.0.19 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 10.0.0 < 10.0.11 | 10.0.11 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 8.0.0 < 8.0.30 | 8.0.30 |
| microsoft | microsoft.netcore.app.runtime.linux-musl-x64 | >= 9.0.0 < 9.0.19 | 9.0.19 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 10.0.0 < 10.0.11 | 10.0.11 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 8.0.0 < 8.0.30 | 8.0.30 |
| microsoft | microsoft.netcore.app.runtime.linux-x64 | >= 9.0.0 < 9.0.19 | 9.0.19 |
| microsoft | microsoft.netcore.app.runtime.osx-arm64 | >= 10.0.0 < 10.0.11 | 10.0.11 |
| microsoft | microsoft.netcore.app.runtime.osx-arm64 | >= 8.0.0 < 8.0.30 | 8.0.30 |
| microsoft | microsoft.netcore.app.runtime.osx-arm64 | >= 9.0.0 < 9.0.19 | 9.0.19 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 10.0.0 < 10.0.11 | 10.0.11 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 8.0.0 < 8.0.30 | 8.0.30 |
| microsoft | microsoft.netcore.app.runtime.osx-x64 | >= 9.0.0 < 9.0.19 | 9.0.19 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
ghsa5.9MEDIUM
vendor_redhat5.9MEDIUM
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2026-08-18·CVSS 5.9
CVE-2026-62909 [MEDIUM] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
Miha Zupan discovered that .NET did not properly interpret certain HTTP
requests. An attacker could possibly use this issue to perform request
smuggling and bypass a security feature. (CVE-2026-62899)
Ivan Demchuk discovered that .NET did not properly handle the removal of
sensitive information before storage or transfer. An attacker could possibly
use this issue to disclose sensitive information. (CVE-2026-62900)
Kevin Gosse discovered that .NET did not properly check an input for a loop
condition. An attacker could possibly use this issue to cause a denial of
service. (CVE-2026-62901)
Kevin Gosse discovered that .NET did not properly perform error checking
when securing shared resources used for diagnos
Red Hat
.NET: .NET Core: System.Net.HttpListener incorrectly parses Content-Length header
vendor_redhat·2026-08-11·CVSS 5.9
CVE-2026-62899 [MEDIUM] CWE-444 .NET: .NET Core: System.Net.HttpListener incorrectly parses Content-Length header
.NET: .NET Core: System.Net.HttpListener incorrectly parses Content-Length header
No description is available for this CVE.
Package: dotnet10.0 (Red Hat Enterprise Linux 10) - Affected
Package: dotnet8.0 (Red Hat Enterprise Linux 10) - Affected
Package: dotnet9.0 (Red Hat Enterprise Linux 10) - Affected
Package: dotnet10.0 (Red Hat Enterprise Linux 8) - Affected
Package: dotnet8.0 (Red Hat Enterprise Linux 8) - Affected
Package: dotnet9.0 (Red Hat Enterprise Linux 8) - Affected
Package: dotnet10.0 (Red Hat Enterprise Linux 9) - Affected
Package: dotnet8.0 (Red Hat Enterprise Linux 9) - Affected
Package: dotnet9.0 (Red Hat Enterprise Linux 9) - Affected
Package: dotnet10.0 (Red Hat Hardened Images) - Fix deferred
Package: dotnet8.0 (Red Hat Hardened Images) - Fix deferred
Packa
VulDB
Microsoft .NET/Visual Studio improper authorization (Nessus ID 335252 / WID-SEC-2026-2761)
vuldb·2026-08-15·CVSS 5.9
CVE-2026-62899 [MEDIUM] Microsoft .NET/Visual Studio improper authorization (Nessus ID 335252 / WID-SEC-2026-2761)
A vulnerability, which was classified as critical, has been found in Microsoft .NET and Visual Studio. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in improper authorization.
This vulnerability is identified as CVE-2026-62899. The attack can be initiated remotely. There is not any exploit available.
It is suggested to install a patch to address this issue.
GHSA
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
ghsa·2026-08-11·CVSS 5.9
CVE-2026-62899 [MEDIUM] CWE-444 Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in System.Net.HttpListener. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/427
## CVSS Details
- **Version:** 3.1
- **Severity:** Medium
- **Score:** 5.9
- **Vector:** `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C`
- **Weakness:**
No detection rules found.
No public exploits indexed.
Rapid7
Patch Tuesday - August 2026
blogs_rapid7·2026-08-11·CVSS 7.2
CVE-2026-68821 [HIGH] Patch Tuesday - August 2026
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month.
## Summary charts
## Summary tables
#
Sans Isc
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
blogs_sans_isc·2026-08-11·CVSS 7.8
CVE-2026-68820 [HIGH] Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
Microsoft Patch Tuesday August 2026
Published: 2026-08-11. Last Updated: 2026-08-11 17:54:49 UTC
by Renato Marinho (Version: 1)
0 comment(s)
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs.
A few vulnerabilities worth mentioning:
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820)
This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancil
Bugzilla
CVE-2026-62899 dotnet9.0: .NET Security Feature Bypass Vulnerability [fedora-all]
bugzilla·2026-08-12·CVSS 5.9
CVE-2026-62899 [MEDIUM] CVE-2026-62899 dotnet9.0: .NET Security Feature Bypass Vulnerability [fedora-all]
CVE-2026-62899 dotnet9.0: .NET Security Feature Bypass Vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
System.Net.HttpListener - managed HttpListener incorrectly parses Content-Length header (Linux/.NET Core only)
Affects: 6.0, 8.0, 9.0, 10.0
Bugzilla
CVE-2026-62899 dotnet8.0: .NET Security Feature Bypass Vulnerability [fedora-all]
bugzilla·2026-08-12·CVSS 5.9
CVE-2026-62899 [MEDIUM] CVE-2026-62899 dotnet8.0: .NET Security Feature Bypass Vulnerability [fedora-all]
CVE-2026-62899 dotnet8.0: .NET Security Feature Bypass Vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
System.Net.HttpListener - managed HttpListener incorrectly parses Content-Length header (Linux/.NET Core only)
Affects: 6.0, 8.0, 9.0, 10.0
Bugzilla
CVE-2026-62899 dotnet10.0: .NET Security Feature Bypass Vulnerability [fedora-all]
bugzilla·2026-08-12·CVSS 5.9
CVE-2026-62899 [MEDIUM] CVE-2026-62899 dotnet10.0: .NET Security Feature Bypass Vulnerability [fedora-all]
CVE-2026-62899 dotnet10.0: .NET Security Feature Bypass Vulnerability [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
System.Net.HttpListener - managed HttpListener incorrectly parses Content-Length header (Linux/.NET Core only)
Affects: 6.0, 8.0, 9.0, 10.0
Bugzilla
CVE-2026-62899 .NET: .NET Core: System.Net.HttpListener incorrectly parses Content-Length header
bugzilla·2026-08-06·CVSS 5.9
CVE-2026-62899 [MEDIUM] CVE-2026-62899 .NET: .NET Core: System.Net.HttpListener incorrectly parses Content-Length header
CVE-2026-62899 .NET: .NET Core: System.Net.HttpListener incorrectly parses Content-Length header
System.Net.HttpListener - managed HttpListener incorrectly parses Content-Length header (Linux/.NET Core only)
Affects: 6.0, 8.0, 9.0, 10.0
2026-08-11
Published