<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Microsoft .NET</title>
  <link>https://cvedaily.com/pages/tags/dotnet.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/dotnet.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Microsoft .NET</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-42191 – OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42191</guid>
    <pubDate>Tue, 12 May 2026 20:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42191</strong></p>
  <p>OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol) exporter implementation. From 1.8.0 to 1.15.2, the OTLP disk retry feature in OpenTelemetry.Exporter.OpenTelemetryProtocol silently fell back to Path.GetTempPath() when OTEL_DOTNET_EXPERIMENTAL_OTLP_RETRY=disk was set but OTEL_DOTNET_EXPERIMENTAL_OTLP_DISK_RETRY_DIRECTORY_PATH was not configured. The exporter stored…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-379</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41078 – OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41078</guid>
    <pubDate>Thu, 23 Apr 2026 19:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41078</strong></p>
  <p>OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow sustained memory pressure when the internal pooled-list sizing grows based on a large observed span/tag set and that enlarged size is reused for subsequent allocations. Under high-cardinality or attacker-influenced telemetry input, this can increase memory consumption and poten…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40894 – OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40894</guid>
    <pubDate>Thu, 23 Apr 2026 19:17:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40894</strong></p>
  <p>OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Extensions.Propagators 1.3.1 to 1.15.2, The implementation details of the baggage, B3 and Jaeger processing code in the OpenTelemetry.Api and OpenTelemetry.Extensions.Propagators NuGet packages can allocate excessive memory when parsing which could create a potential denial of servi…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40891 – OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40891</guid>
    <pubDate>Thu, 23 Apr 2026 18:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40891</strong></p>
  <p>OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry over gRPC using the OpenTelemetry Protocol (OTLP), the exporter may parse a server-provided grpc-status-details-bin trailer during retry handling. Prior to the fix, a malformed trailer could encode an extremely large length-delimited protobuf field which was used directly for allocation, a…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40182 – OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40182</guid>
    <pubDate>Thu, 23 Apr 2026 18:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40182</strong></p>
  <p>OpenTelemetry dotnet is a dotnet telemetry framework. From 1.13.1 to before 1.15.2, When exporting telemetry to a back-end/collector over gRPC or HTTP using OpenTelemetry Protocol format (OTLP), if the request results in a unsuccessful request (i.e. HTTP 4xx or 5xx), the response is read into memory with no upper-bound on the number of bytes consumed. This could cause memory exhaustion in the con…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36855 – A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36855</guid>
    <pubDate>Mon, 08 Sep 2025 14:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36855</strong></p>
  <p>A vulnerability ( CVE-2025-21176 https://www.cve.org/CVERecord ) exists in DiaSymReader.dll due to buffer over-read.   Per  CWE-126: Buffer Over-read https://cwe.mitre.org/data/definitions/126.html , Buffer Over-read is when a product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.    This issue affects EOL…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-126</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36854 – A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36854</guid>
    <pubDate>Mon, 08 Sep 2025 14:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36854</strong></p>
  <p>A vulnerability ( CVE-2024-38229 https://www.cve.org/CVERecord ) exists in EOL ASP.NET when closing an HTTP/3 stream while application code is writing to the response body, a race condition may lead to use-after-free, resulting in Remote Code Execution.    Per  CWE-416: Use After Free https://cwe.mitre.org/data/definitions/416.html , Use After Free is when a product reuses or references memory af…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27513 – OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27513</guid>
    <pubDate>Wed, 05 Mar 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27513</strong></p>
  <p>OpenTelemetry dotnet is a dotnet telemetry framework. A vulnerability in OpenTelemetry.Api package 1.10.0 to 1.11.1 could cause a Denial of Service (DoS) when a tracestate and traceparent header is received. Even if an application does not explicitly use trace context propagation, receiving these headers can still trigger high CPU usage. This issue impacts any application accessible over the web…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10125 – The  Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10125</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10125</guid>
    <pubDate>Tue, 22 Oct 2024 00:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10125</strong></p>
  <p>The  Amazon.ApplicationLoadBalancer.Identity.AspNetCore repo https://github.com/awslabs/aws-alb-identity-aspnetcore#validatetokensignature  contains Middleware that can be used in conjunction with the Application Load Balancer (ALB) OpenId Connect integration and can be used in any  ASP.NET https://dotnet.microsoft.com/apps/aspnet  Core deployment scenario, including Fargate, EKS, ECS, EC2, and L…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10125">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35240 – Umbraco Commerce is an open source dotnet ecommerce solution. In affected versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35240</guid>
    <pubDate>Tue, 28 May 2024 21:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35240</strong></p>
  <p>Umbraco Commerce is an open source dotnet ecommerce solution. In affected versions there exists a stored Cross-site scripting (XSS) issue which would enable attackers to inject malicious code into Print Functionality. This issue has been addressed in versions 12.1.4, and 10.0.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-35239 – Umbraco Commerce is an open source dotnet web forms solution. In affected versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35239</guid>
    <pubDate>Tue, 28 May 2024 21:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-35239</strong></p>
  <p>Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access to edit Forms may inject unsafe code into Forms components. This issue can be mitigated by configuring TitleAndDescription:AllowUnsafeHtmlRendering after upgrading to one of the patched versions (13.0.1, 12.2.2, 10.5.3, 8.13.13).</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-32028 – OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32028</guid>
    <pubDate>Fri, 12 Apr 2024 23:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-32028</strong></p>
  <p>OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `OpenTelemetry.Instrumentation.AspNetCore` the `url.full` writes attribute/tag on spans (`Activity`) when tracing is enabled for outgoing http requests and `OpenTelemetry.Instrumentation.AspNetCore` writes the `url.query` attribute/tag on spans (`Activity`) when tracing is enable…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-23838 – TrueLayer.NET is the .Net client for TrueLayer.  The vulnerability could potenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23838</guid>
    <pubDate>Tue, 30 Jan 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-23838</strong></p>
  <p>TrueLayer.NET is the .Net client for TrueLayer.  The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient used in the API classes. For applications using the SDK, requests to unexpected resources on local networks or to the internet could be made which could lead to information disclosure. The issue can be mitigated by having strict eg…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-43569 – The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43569</guid>
    <pubDate>Tue, 09 Nov 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-43569</strong></p>
  <p>The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19396 – ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19396</guid>
    <pubDate>Tue, 20 Nov 2018 21:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19396</strong></p>
  <p>ext/standard/var_unserializer.c in PHP 5.x through 7.1.24 allows attackers to cause a denial of service (application crash) via an unserialize call for the com, dotnet, or variant class.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-19395 – ext/standard/var.c in PHP 5.x through 7.1.24 on Windows allows attackers to caus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19395</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19395</guid>
    <pubDate>Tue, 20 Nov 2018 21:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-19395</strong></p>
  <p>ext/standard/var.c in PHP 5.x through 7.1.24 on Windows allows attackers to cause a denial of service (NULL pointer dereference and application crash) because com and com_safearray_proxy return NULL in com_properties_get in ext/com_dotnet/com_handlers.c, as demonstrated by a serialize call on COM("WScript.Shell").</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19395">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-4153 – PHP 5.3.8 does not always check the return value of the zend_strndup function, w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-4153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-4153</guid>
    <pubDate>Wed, 18 Jan 2012 20:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-4153</strong></p>
  <p>PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted input to an application that performs strndup operations on untrusted string data, as demonstrated by the define function in zend_builtin_functions.c, and unspecified functions in ext/soap/php_sd…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-4153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-4514 – Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4514</guid>
    <pubDate>Thu, 09 Dec 2010 21:00:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-4514</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4514">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
