{
  "threat_severity" : "Moderate",
  "public_date" : "2026-08-11T00:00:00Z",
  "bugzilla" : {
    "description" : ".NET: .NET Core: .NET Security Feature Bypass Vulnerability",
    "id" : "2512175",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2512175"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.9",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-444",
  "details" : [ "Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.", "Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network." ],
  "statement" : "This Moderate impact flaw in System.Net.HttpListener on Red Hat platforms running .NET Core allows for a security feature bypass. The vulnerability arises from incorrect parsing of the Content-Length header, potentially affecting applications that utilize HttpListener to process HTTP requests.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54541",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "dotnet8.0-0:8.0.130-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54590",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "dotnet9.0-0:9.0.120-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55858",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "dotnet10.0-0:10.0.111-1.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58566",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "dotnet8.0-0:8.0.130-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10.0 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58567",
    "cpe" : "cpe:/o:redhat:enterprise_linux_eus:10.0",
    "package" : "dotnet9.0-0:9.0.120-1.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54538",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "dotnet8.0-0:8.0.130-1.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54542",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "dotnet10.0-0:10.0.111-1.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54550",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "dotnet9.0-0:9.0.120-1.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-13T00:00:00Z",
    "advisory" : "RHSA-2026:54574",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "dotnet8.0-0:8.0.130-1.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55856",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "dotnet9.0-0:9.0.120-1.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-08-17T00:00:00Z",
    "advisory" : "RHSA-2026:55857",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "dotnet10.0-0:10.0.111-1.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58568",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.4",
    "package" : "dotnet8.0-0:8.0.130-1.el9_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58569",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "dotnet8.0-0:8.0.130-1.el9_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.6 Extended Update Support",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58570",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.6",
    "package" : "dotnet9.0-0:9.0.120-1.el9_6"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-24T00:00:00Z",
    "advisory" : "RHSA-2026:44914",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "dotnet9-0-main-9.0.119-2.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-08-15T00:00:00Z",
    "advisory" : "RHSA-2026:55142",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "dotnet10-0-main-10.0.11-1.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-08-16T00:00:00Z",
    "advisory" : "RHSA-2026:55405",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "dotnet8-0-main-8.0.130-0.1.hum1"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenShift Dev Spaces",
    "fix_state" : "Fix deferred",
    "package_name" : "devspaces/udi-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_devspaces:3"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-62899\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-62899" ],
  "name" : "CVE-2026-62899",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}