CVE-2026-62899

Updated on 11 Aug 2026

Severity

5.9 Medium severity

Details

CVSS score
5.9
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Overview

About vulnerability

Inconsistent interpretation of http requests (‘http request/response smuggling’) in .NET allows an unauthorized attacker to bypass a security feature over a network.

Details

Affected product:
Debian 12 , Debian 13 , Windows 10
Affected packages:
dotnet @ 6.0.36 (+4 more)