USN-8740-1
Dashboard / Vulnerabilities / USN-8740-1
USN-8740-1
Summary: dotnet8, dotnet10 vulnerabilities
Details: Weeraphat Srisutham discovered that the .NET watch BrowserRefreshServer did not properly validate cross-origin WebSocket connections. An attacker could possibly use this issue to expose sensitive information. (CVE-2026-58649) Rajesh Chada discovered that the .NET watch AspireServerService improperly exposed information through the use of certain arguments. An attacker could possibly use this issue to elevate privileges and execute arbitrary code. (CVE-2026-69806)
References: https://ubuntu.com/security/notices/USN-8740-1, https://ubuntu.com/security/CVE-2026-58649, https://ubuntu.com/security/CVE-2026-69806
Affected packages
Package
Name: dotnet8
Purl: pkg:deb/ubuntu/dotnet8?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
