Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.5
CVE-2026-57108: Microsoft .NET Core Network Denial of Service
CVE-2026-57108
CVE-2026-57108
GHSA-rp2p-6cmp-jxj9
BIT-dotnet-sdk-2026-57108
Summary
An attacker can cause .NET Core servers to become unresponsive, disrupting service to users. This affects .NET Core applications, which should be updated to the latest version to prevent service disruptions. Patching or upgrading to the latest version is recommended.
What to do
- Update microsoft.netcore.app.runtime.linux-arm to version 10.0.10.
- Update microsoft.netcore.app.runtime.linux-arm64 to version 10.0.10.
- Update microsoft.netcore.app.runtime.linux-musl-arm to version 10.0.10.
- Update microsoft.netcore.app.runtime.linux-musl-arm64 to version 10.0.10.
- Update microsoft.netcore.app.runtime.linux-musl-x64 to version 10.0.10.
- Update microsoft.netcore.app.runtime.linux-x64 to version 10.0.10.
- Update microsoft.netcore.app.runtime.osx-arm64 to version 10.0.10.
- Update microsoft.netcore.app.runtime.osx-x64 to version 10.0.10.
- Update microsoft.netcore.app.runtime.linux-arm to version 9.0.18.
- Update microsoft.netcore.app.runtime.linux-arm64 to version 9.0.18.
- Update microsoft.netcore.app.runtime.linux-musl-arm to version 9.0.18.
- Update microsoft.netcore.app.runtime.linux-musl-arm64 to version 9.0.18.
- Update microsoft.netcore.app.runtime.linux-musl-x64 to version 9.0.18.
- Update microsoft.netcore.app.runtime.linux-x64 to version 9.0.18.
- Update microsoft.netcore.app.runtime.osx-arm64 to version 9.0.18.
- Update microsoft.netcore.app.runtime.osx-x64 to version 9.0.18.
- Update microsoft.netcore.app.runtime.linux-arm to version 8.0.29.
- Update microsoft.netcore.app.runtime.linux-arm64 to version 8.0.29.
- Update microsoft.netcore.app.runtime.linux-musl-arm to version 8.0.29.
- Update microsoft.netcore.app.runtime.linux-musl-arm64 to version 8.0.29.
- Update microsoft.netcore.app.runtime.linux-musl-x64 to version 8.0.29.
- Update microsoft.netcore.app.runtime.linux-x64 to version 8.0.29.
- Update microsoft.netcore.app.runtime.osx-arm64 to version 8.0.29.
- Update microsoft.netcore.app.runtime.osx-x64 to version 8.0.29.
- Update dotnet to version 10.0.6.
- Update dotnet-sdk to version 10.0.6.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | microsoft | .net 10.0 |
< 5104034 < 10.0.6 |
| – | microsoft | .net 8.0 | < 8.0.29 |
| – | microsoft | .net 9.0 | < 9.0.18 |
| – | microsoft | .net |
>= 8.0.0, < 8.0.29 >= 9.0.0, < 9.0.18 >= 10.0.0, < 10.0.6 cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* |
| nuget | – | microsoft.netcore.app.runtime.linux-arm |
>= 10.0.0, <= 10.0.9 >= 9.0.0, <= 9.0.17 >= 8.0.0, <= 8.0.28 Fix: upgrade to 10.0.10
|
| nuget | – | microsoft.netcore.app.runtime.linux-arm64 |
>= 10.0.0, <= 10.0.9 >= 9.0.0, <= 9.0.17 >= 8.0.0, <= 8.0.28 Fix: upgrade to 10.0.10
|
| nuget | – | microsoft.netcore.app.runtime.linux-musl-arm |
>= 10.0.0, <= 10.0.9 >= 9.0.0, <= 9.0.17 >= 8.0.0, <= 8.0.28 Fix: upgrade to 10.0.10
|
| nuget | – | microsoft.netcore.app.runtime.linux-musl-arm64 |
>= 10.0.0, <= 10.0.9 >= 9.0.0, <= 9.0.17 >= 8.0.0, <= 8.0.28 Fix: upgrade to 10.0.10
|
| nuget | – | microsoft.netcore.app.runtime.linux-musl-x64 |
>= 10.0.0, <= 10.0.9 >= 9.0.0, <= 9.0.17 >= 8.0.0, <= 8.0.28 Fix: upgrade to 10.0.10
|
| nuget | – | microsoft.netcore.app.runtime.linux-x64 |
>= 10.0.0, <= 10.0.9 >= 9.0.0, <= 9.0.17 >= 8.0.0, <= 8.0.28 Fix: upgrade to 10.0.10
|
| nuget | – | microsoft.netcore.app.runtime.osx-arm64 |
>= 10.0.0, <= 10.0.9 >= 9.0.0, <= 9.0.17 >= 8.0.0, <= 8.0.28 Fix: upgrade to 10.0.10
|
| nuget | – | microsoft.netcore.app.runtime.osx-x64 |
>= 10.0.0, <= 10.0.9 >= 9.0.0, <= 9.0.17 >= 8.0.0, <= 8.0.28 Fix: upgrade to 10.0.10
|
| Bitnami | – | dotnet |
>= 10.0.0, < 10.0.6 Fix: upgrade to 10.0.6
|
| Bitnami | – | dotnet-sdk |
>= 10.0.0, < 10.0.6 Fix: upgrade to 10.0.6
|
Original title
.NET Denial of Service Vulnerability
Original description
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
mitre CVSS3.1
7.5
Vulnerability type
CWE-843
Type Confusion
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57108 vendor-advisory patch
- https://github.com/dotnet/runtime/security/advisories/GHSA-rp2p-6cmp-jxj9
- https://nvd.nist.gov/vuln/detail/CVE-2026-57108
- https://github.com/dotnet/announcements/issues/408
- https://github.com/dotnet/runtime/issues/130707
- https://github.com/advisories/GHSA-rp2p-6cmp-jxj9
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 14 Jul 2026