It was discovered that .NET did not properly handle the creation of temporary build time directories. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-55247) It was discovered that .NET did not properly establish TLS sessions for SMTP server connections. An attacker could use this issue to cause .NET to use unencrypted connections. This issue only affects .NET versions 8.0 and 9.0. (CVE-2025-55248) It was discovered that .NET inconsistently interpreted certain http requests. An attacker could possibly use this to bypass a security feature over a network. (CVE-2025-55315)
Continue reading...
Continue reading...

