Back to blog

// OSSeva Blog

Security

.NET Vulnerabilities by Version: CVEs for .NET 6, 7, 8, 9 and 10

Randall McClure8 min read

The short answer

Microsoft supports three .NET lines. .NET 10 is a long-term support release, supported until 14 November 2028. .NET 8, also LTS, and .NET 9, a standard-term release, are both supported until 10 November 2026, because Microsoft gives LTS releases three years and STS releases two. .NET 7 ended on 14 May 2024 and .NET 6 on 12 November 2024. Microsoft's release metadata lists 45 CVEs fixed in .NET 8 releases so far in 2026, 47 in .NET 9 and 49 in .NET 10. Microsoft does not assess .NET 6 or 7 for new CVEs: since their last releases it has fixed 55 CVEs in .NET 8 that came after 6.0.36, and 65 that came after 7.0.20. On 10 November 2026, .NET 8 and 9 join them.

.NET release lines and their CVEs

Dates, support phases and CVE lists are from Microsoft's .NET release metadata, which backs the .NET support policy page and the release notes in the dotnet/core repository.

LineType and statusLatest releaseCVEs fixed on this line in 2026Upstream fix on this line
.NET 10LTS; supported until 14 November 202810.0.12, 8 September 202649All 49, by 10.0.12
.NET 9STS; supported until 10 November 20269.0.20, 8 September 202647All 47, by 9.0.20
.NET 8LTS; supported until 10 November 20268.0.31, 8 September 202645All 45, by 8.0.31
.NET 7STS; ended 14 May 20247.0.20, 28 May 2024Not assessed; 65 CVEs fixed in .NET 8 since 7.0.20No upstream fix on this line
.NET 6LTS; ended 12 November 20246.0.36, 12 November 2024; last security fixes in 6.0.35Not assessed; 55 CVEs fixed in .NET 8 since 6.0.36No upstream fix on this line
.NET 5 and .NET Core 3.1Ended 10 May 2022 and 13 December 20225.0.17; 3.1.32Not assessedNo upstream fix on these lines

"Not assessed" means Microsoft's advisories for these CVEs list .NET 8, 9 and 10 and say nothing about the older lines. It does not mean they are safe. Not every CVE applies to every application: some are in ASP.NET Core components such as Kestrel, SignalR or Negotiate authentication, some only in the Windows Desktop runtime or Windows builds, and some only in the SDK. See the .NET end of life tracker for every line.

Notable .NET CVEs by release line

CVSS is NVD's own score where NVD has scored the record, otherwise Microsoft's score as the CNA. Two .NET CVEs are in CISA's Known Exploited Vulnerabilities catalogue, CVE-2023-38180, added on 9 August 2023, and CVE-2023-44487, the HTTP/2 Rapid Reset flaw, added on 10 October 2023. Both were fixed on .NET 6 and 7 before they ended.

CVEIssueCVSSFixed inLines with no fix
CVE-2025-55315HTTP request smuggling in the ASP.NET Core Kestrel server lets an authenticated attacker bypass security features9.9 (Microsoft)8.0.21, 9.0.10, 10.0.0; Kestrel.Core 2.3 package6.0 and 7.0 not assessed
CVE-2026-47304EncryptedXml in System.Security.Cryptography.Xml fails to verify signatures properly, exposing encrypted data9.8 (NVD)8.0.29, 9.0.18, 10.0.106.0 and 7.0 not assessed
CVE-2026-40372ASP.NET Core Data Protection 10.0.0 to 10.0.6 lets attackers forge authentication cookies and decrypt some payloads9.1 (Microsoft)10.0.7Only 10.0 is affected
CVE-2026-47303Improper parsing in the ASP.NET Core Negotiate authentication handler allows elevation of privilege8.8 (Microsoft)8.0.29, 9.0.18, 10.0.106.0 and 7.0 not assessed
CVE-2026-47300Negotiate authentication with LDAP role lookup validates incorrectly, allowing elevation of privilege8.8 (Microsoft)8.0.29, 9.0.18, 10.0.106.0 and 7.0 not assessed
CVE-2026-50528SslStream can be made to skip authorization checks on TLS connections8.2 (Microsoft)8.0.29, 9.0.18, 10.0.106.0 and 7.0 not assessed
CVE-2026-62898Use after free in Microsoft QUIC on Windows discloses memory to an unauthenticated client7.5 (Microsoft)8.0.30, 9.0.19, 10.0.116.0 and 7.0 not assessed
CVE-2026-45591Deeply nested MessagePack arrays overflow the stack in SignalR and Blazor Server7.5 (Microsoft)8.0.28, 9.0.17, 10.0.96.0 and 7.0 not assessed
CVE-2024-0057X.509 chain building returns the wrong failure reason for certificates with malformed signatures, which apps can mistake for success9.8 (NVD)8.0.1, 7.0.15, 6.0.26None of the lines in this guide
CVE-2023-44487HTTP/2 Rapid Reset floods Kestrel with request cancellations7.5 (NVD)7.0.12, 6.0.23, and 8.0 before its releaseNone of the lines in this guide
CVE-2023-38180Kestrel sometimes fails to disconnect a client it has flagged as malicious7.5 (Microsoft)7.0.10, 6.0.21None of the lines in this guide

The last three rows show the pattern for an end-of-life .NET line: CVEs Microsoft listed for .NET 6 and 7 while they were supported have fixes in their final releases, and nothing published since has one. The 2026 list is weighted toward ASP.NET Core and TLS: Kestrel request handling, Negotiate authentication, Data Protection, SslStream and EncryptedXml. For an internet-facing ASP.NET Core application on .NET 6 or 7, CVE-2025-55315 is the one to look at first, and Microsoft's advisory lists no mitigating factors for it.

What each line gets

.NET 10

10.0.12 has every fix above that applies to it. If an application ran on 10.0.0 to 10.0.6 with Data Protection, upgrading is not enough for CVE-2026-40372: Microsoft says tokens issued with forged payloads stay valid after the upgrade unless the Data Protection key ring is rotated.

.NET 8 and .NET 9

8.0.31 and 9.0.20 have every 2026 fix that lists them. Both lines leave support on 10 November 2026, so .NET 9 does not buy time over .NET 8. The move to .NET 10 changes the target framework and SDK, and brings the breaking changes in .NET 9 and 10 at once. See .NET 8 end of life, .NET 9 end of life and the .NET 8 to .NET 10 upgrade guide.

.NET 7

7.0.20, from 28 May 2024, is the last release, and it includes the fixes for CVE-2024-0057, CVE-2023-44487 and CVE-2023-38180. It has nothing for the 65 CVEs fixed in .NET 8 since then, including CVE-2025-55315 and the 2026 ASP.NET Core authentication flaws. See .NET 7 end of life.

.NET 6

6.0.35, from 8 October 2024, carried the last .NET 6 security fixes, for CVE-2024-43483, CVE-2024-43484 and CVE-2024-43485, and 6.0.36 in November 2024 was the final release. Many applications stayed on .NET 6 because it was LTS, and they now have no upstream fix for any of the 55 CVEs fixed in .NET 8 since. See .NET 6 end of life.

What to do on each line

  • .NET 10. Stay on the latest patch release, and rotate the Data Protection key ring if you ran 10.0.0 to 10.0.6.
  • .NET 8 and 9. Move to 8.0.31 or 9.0.20 now and plan the move to .NET 10 before 10 November 2026, or arrange patched builds for after that date.
  • .NET 6 and 7. Upgrade to .NET 10, or take patched builds. Until then, put Kestrel behind a reverse proxy or web application firewall that normalises HTTP requests, turn off HTTP/2 and HTTP/3 on endpoints that do not need them, and review where you use Negotiate authentication with LDAP roles, SignalR with MessagePack, or EncryptedXml.

Where OSSeva fits

OSSeva ships patched .NET 6 and .NET 7 runtimes, including ASP.NET Core, and covers .NET 8 and .NET 9 after Microsoft's 10 November 2026 date. OSSeva backports fixes of this class to the end-of-life release lines it patches, and delivers them as signed Docker images, apt and yum packages and binaries. They are available now on the Patch, Assure and Operate tiers. Assure adds NuGet dependency vulnerability scanning, an ASP.NET Core TLS and authentication configuration review and a compliance attestation package, and Operate adds 24/7 CLR and application health monitoring with a 15-minute P1 response and a named senior .NET engineer. See .NET extended support.

Tags

.NETCVE.NET 8.NET 6End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.