Résumé
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability
Détails de l’avis
Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET SMTP client (System.Net.Mail). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A spoofing vulnerability exists in the SMTP client implementation (System.Net.Mail) in .NET 8, .NET 9, and .NET 10, where an attacker can spoof messages during message routing.
Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/**TBD**
CVSS Details
- Version: 3.1
- Severity: Medium
- Score: 6.5
- Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N - Weakness: CWE-116 (Improper Encoding or Escaping of Output)
Affected Platforms
- Platforms: All
- Architectures: All
Affected Packages
The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below
.NET 10.0
| Package name | Affected version | Patched version |
|---|---|---|
| Microsoft.NetCore.App.Runtime.linux-arm | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.linux-arm64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.linux-musl-x64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.linux-x64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.osx-arm64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.osx-x64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.win-arm | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.win-arm64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.win-x64 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
| Microsoft.NetCore.App.Runtime.win-x86 | >= 10.0.0, <= 10.0.9 | 10.0.10 |
.NET 9.0
| Package name | Affected version | Patched version |
|---|---|---|
| Microsoft.NetCore.App.Runtime.linux-arm | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.linux-arm64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.linux-musl-x64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.linux-x64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.osx-arm64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.osx-x64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.win-arm | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.win-arm64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.win-x64 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
| Microsoft.NetCore.App.Runtime.win-x86 | >= 9.0.0, <= 9.0.17 | 9.0.18 |
.NET 8.0
| Package name | Affected version | Patched version |
|---|---|---|
| Microsoft.NetCore.App.Runtime.linux-arm | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.linux-arm64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.linux-musl-arm64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.linux-musl-x64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.linux-x64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.osx-arm64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.osx-x64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.win-arm | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.win-arm64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.win-x64 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
| Microsoft.NetCore.App.Runtime.win-x86 | >= 8.0.0, <= 8.0.28 | 8.0.29 |
Advisory FAQ
How do I know if I am affected?
If using a package listed in affected packages, you're exposed to the vulnerability.
How do I fix the issue?
- To fix the issue please install the latest version of .NET. If you have installed one or more .NET SDKs through Visual Studio, Visual Studio will prompt you to update Visual Studio, which will also update your .NET SDKs.
- If your application references the vulnerable nuget package, update the package reference to the patched version. You can list the versions you have installed by running the
dotnet --infocommand.
Once you have installed the updated runtime or SDK, restart your app
Références
- https://github.com/advisories/GHSA-74jp-vm22-8q8x
- https://github.com/dotnet/runtime/security/advisories/GHSA-74jp-vm22-8q8x
- https://nvd.nist.gov/vuln/detail/CVE-2026-50659
- https://github.com/dotnet/announcements/issues/423
- https://github.com/dotnet/runtime/issues/130716
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50659
Vulnérabilités liées
Tout Supply chain →- CRITICALCVE-2026-62681
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
- CRITICALCVE-2026-62682
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
- CRITICALCVE-2026-72717
Orval: Import-time RCE via schema default -> zod module-level template literal
- CRITICALCVE-2026-71869
Orval: Import-time RCE via array-items default -> zod module-level template literal
- CRITICALCVE-2026-71871
Orval: Import-time RCE via header-parameter default -> zod module-level template literal
- CRITICALCVE-2026-71865
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli