CVE-2026-62899: .NET Security Feature Bypass Vulnerability
.NET Security Feature Bypass Vulnerability
Other sources
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.0.30Patch KB5122104 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.19Patch KB5122105 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.14.38 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.11Patch KB5122106 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.8.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62899?
CVE-2026-62899 has a severity rating of medium with a score of 5.9.
What types of software are affected by CVE-2026-62899?
CVE-2026-62899 affects Microsoft .NET 8.0 and 9.0 on various operating systems, including Windows, Mac OS, and Linux.
How does CVE-2026-62899 exploit occur?
CVE-2026-62899 allows an unauthorized attacker to bypass security features through inconsistent interpretation of HTTP requests.
What is the impact of CVE-2026-62899 on security?
The impact of CVE-2026-62899 is that it can potentially allow attackers to bypass security mechanisms over a network.
How do I fix CVE-2026-62899?
To fix CVE-2026-62899, ensure that you are using the latest security patches and updates provided by Microsoft for the affected .NET versions.