<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Microsoft .NET (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/dotnet.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/dotnet-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Microsoft .NET (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-36855 – A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36855</guid>
    <pubDate>Mon, 08 Sep 2025 14:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36855</strong></p>
  <p>A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read.   Per  CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.    This issue affects EOL…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36854 – A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36854</guid>
    <pubDate>Mon, 08 Sep 2025 14:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36854</strong></p>
  <p>A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution.    Per  CWE-416: Use After Free https://cwe.mitre.org/data/definitions/416.html , Use After Free is when a product reuses or references memory af…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27513 – OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27513</guid>
    <pubDate>Wed, 05 Mar 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27513</strong></p>
  <p>OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTelemetry.Api package 1.10.0 to 1.11.1 could cause a Denial of Service (DoS) when a tracestate and traceparent header is received. Even if an application does not explicitly use trace context propagation, receiving these headers can still trigger high CPU usage. This issue impacts any application accessible over the web…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10125 – The  Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10125</guid>
    <pubDate>Tue, 22 Oct 2024 00:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10125</strong></p>
  <p>The  Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/awslabs/aws-alb-identity-aspnetcore#validatetokensignature  contains Middleware that can be used in conjunction with the Application Load Balancer (ALB) OpenId Connect integration and can be used in any  ASP.NET https://dotnet.microsoft.com/apps/aspnet  Core deployment scenario, including Fargate, EKS, ECS, EC2, and L…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23838 – TrueLayer.NET is the .Net client for TrueLayer.  The vulnerability could potenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23838</guid>
    <pubDate>Tue, 30 Jan 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23838</strong></p>
  <p>TrueLayer.NET is the .Net client for TrueLayer.  The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient used in the API classes. For applications using the SDK, requests to unexpected resources on local networks or to the internet could be made which could lead to information disclosure. The issue can be mitigated by having strict eg…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-43569 – The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43569</guid>
    <pubDate>Tue, 09 Nov 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-43569</strong></p>
  <p>The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19396 – ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19396</guid>
    <pubDate>Tue, 20 Nov 2018 21:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19396</strong></p>
  <p>ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19395 – ext/standard/var.c in PHP 5.x through 7.1.24 on Windows allows attackers to caus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19395</guid>
    <pubDate>Tue, 20 Nov 2018 21:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19395</strong></p>
  <p>ext/standard/var.c in PHP 5.x through 7.1.24 on Windows allows attackers to cause a denial of service (NULL pointer dereference and application crash) because com and com_safearray_proxy return NULL in com_properties_get in ext/com_dotnet/com_handlers.c, as demonstrated by a serialize call on COM("WScript.Shell").</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19395">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
