PT-2026-24330 · Microsoft+4 · Microsoft.Bcl.Memory 9.0.0+11
CVE-2026-26127
·
Publicado
2026-03-10
·
Atualizado
2026-05-21
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
.NET versions 9.0.0 through 9.0.13
.NET versions 10.0.0 through 10.0.3
Microsoft.Bcl.Memory versions 9.0.0 through 9.0.13
Microsoft.Bcl.Memory versions 10.0.0 through 10.0.3
Description
An out-of-bounds read issue exists in .NET and Microsoft.Bcl.Memory when decoding malformed Base64Url input. This can allow an unauthorized attacker to cause a denial of service (DoS) over a network, potentially preventing legitimate users from accessing the affected service. Approximately 32 articles have been published from different internet sources regarding this issue.
Recommendations
For .NET 9.0.0 through 9.0.13, update to version 9.0.14.
For .NET 10.0.0 through 10.0.3, update to version 10.0.4.
For Microsoft.Bcl.Memory versions 9.0.0 through 9.0.13, update to version 9.0.14.
For Microsoft.Bcl.Memory versions 10.0.0 through 10.0.3, update to version 10.0.4.
To update packages, use the NuGet Package Manager UI in Visual Studio, the NuGet Package Manager Console, or the .NET CLI with the appropriate
update-package or dotnet package update command.Correção
DoS
Improper Validation of Array Index
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
.Net 10.0.0
.Net 10.0.3
.Net 9.0.0
.Net 9.0.13
Linuxmint
Microsoft.Bcl.Memory 10.0.0
Microsoft.Bcl.Memory 10.0.3
Microsoft.Bcl.Memory 9.0.0
Microsoft.Bcl.Memory 9.0.13
Red Os
Rocky Linux
Ubuntu