REDHAT-BUG-2512175: Medium severity Microsoft System.Net.HttpListener vulnerability
Published Aug 6, 2026
·Updated
System.Net.HttpListener - managed HttpListener incorrectly parses Content-Length header (Linux/.NET Core only)
Affects: 6.0, 8.0, 9.0, 10.0
Affected Software
1 affected component
Microsoft System.Net.HttpListener>=6.0<=10.0
Event History
Aug 6, 2026
Data Sourced
via Red Hat·08:40 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2512175?
The severity of REDHAT-BUG-2512175 is medium with a risk level of 4.
2
What versions of Microsoft System.Net.HttpListener are affected by REDHAT-BUG-2512175?
REDHAT-BUG-2512175 affects versions 6.0, 8.0, 9.0, and 10.0 of Microsoft System.Net.HttpListener.
3
How do I mitigate the risks associated with REDHAT-BUG-2512175?
To mitigate the risks of REDHAT-BUG-2512175, ensure that your application properly validates Content-Length headers and apply any available patches.
4
What is the description of REDHAT-BUG-2512175?
REDHAT-BUG-2512175 describes a vulnerability in System.Net.HttpListener where the Content-Length header is incorrectly parsed on Linux/.NET Core.
5
When was REDHAT-BUG-2512175 published?
REDHAT-BUG-2512175 was published on August 6, 2026.