CVE-2026-47304

Aliases:GHSA-g8r8-53c2-pm3fUBUNTU-CVE-2026-47304BIT-dotnet-2026-47304BIT-dotnet-sdk-2026-47304CGA-27vq-22rh-w5m2CGA-2h67-5p83-cq3qCGA-2j22-7q9g-7fwrCGA-2mqw-8mcm-xxrxCGA-323r-6848-vrq3CGA-386j-3xrw-mqp2CGA-387r-w46j-248rCGA-38h7-hm7h-r4jfCGA-3fqj-9vjh-pmwpCGA-3hf4-8fw6-p7ghCGA-3v4x-9wxx-j3gjCGA-3wvq-j4f8-v64gCGA-5559-39qh-mwcvCGA-55gv-c528-37mfCGA-5gpm-5vr8-8735CGA-5j9x-6r6f-mv9fCGA-5pr7-7cg2-q5q3CGA-6hhv-rp3m-322gCGA-6m53-94hx-cc9wCGA-6wfm-mww9-pfr2CGA-6x5w-mc48-2p53CGA-6x8f-9m4c-vcrmCGA-83m2-7g5m-mfjqCGA-8689-6668-f24rCGA-8pvp-c443-29vcCGA-8vpv-ccmg-r27vCGA-8wf3-7pjp-r38gCGA-93gf-4vwq-h277CGA-93vr-q76c-r93gCGA-94v3-79r7-2982CGA-987h-hgcx-2pg5CGA-9q8c-8gpx-9w2pCGA-9wg5-9gv5-p93fCGA-c5jj-9mh9-38p3CGA-chgp-ppm2-29cjCGA-cjfc-qqpm-vpp5CGA-cqfc-7x9h-3x93CGA-cw7h-9938-84qvCGA-f8x2-227r-5xc2CGA-ghp6-7fq5-vm77CGA-gmvr-fvx8-mq83CGA-h3fg-4pg6-r72wCGA-h3gq-pq34-f8q9CGA-h3jf-mhgw-7p5hCGA-hh3w-p72g-jfmgCGA-hxqr-vmqc-344jCGA-j7rr-pmpr-2cgwCGA-j98x-vhpq-2g44CGA-jpqq-6947-pxqrCGA-jqv5-2hhx-8379CGA-jxjc-4r72-qw8vCGA-mj9r-qq3g-r5xrCGA-p4c8-r775-ccvmCGA-p76m-xh55-7fj5CGA-pm63-m4w7-4gmvCGA-q7pw-vvr9-9vjjCGA-qgx2-hwc2-c739CGA-rj9h-gp8j-9prrCGA-rmx2-fxv6-94f4CGA-rrwq-8pgx-gc7jCGA-rvrg-xj53-pcg3CGA-v2x2-592x-4p69CGA-vhxv-m9pm-x8prCGA-vjx7-39qg-gpgqCGA-vr92-hh6v-gj8wCGA-w3mc-gpwx-ffpcCGA-w7vm-f5x4-686hCGA-wf59-grjh-r5hmCGA-wgc3-wrj4-3fc2CGA-wj47-rrpc-55vwCGA-x62q-vpph-g4q9CGA-xm54-mmpf-wpg3CGA-xr8j-fpr4-fcq2CGA-xx62-pfc7-v4wpCGA-cmcx-52hw-74mh
Advisory lineage Upstream: 0 Downstream: 17
Analyzed
Published: 14 Jul 2026, 18:45
Last modified:17 Sept 2026, 22:29

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
0.22% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Jul 2026, 18:45
Published
Vulnerability first disclosed
17 Sept 2026, 22:29
Last Modified
Vulnerability information updated

Description

Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.22% Percentile: 12%

Techniques & Countermeasures

  • CWE-347Improper Verification of Cryptographic Signature

    The product does not verify, or incorrectly verifies, the cryptographic signature for data.

  • CWE-345Insufficient Verification of Data Authenticity

    The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Systems

  • chainguardaspnet-8-targeting-pack

    < 8.0.131-r0

  • chainguarddotnet-8-sdk

    < 8.0.129-r1

  • chainguarddotnet-bootstrap-8

    < 8.0.129-r0 | < 8.0.130-r0

  • chainguarddotnet-bootstrap-9

    < 9.0.120-r0

  • chainguarddotnet-sdk-10.0.2

    < 10.0.204-r4

  • chainguarddotnet-sdk-10.0.3

    < 10.0.301-r5

  • chainguardpowershell

    < 7.6.4-r1

  • chainguardpromitor

    < 2.16.0-r3

  • wolfiaspnet-8-targeting-pack

    < 8.0.131-r0

  • wolfidotnet-8-sdk

    < 8.0.129-r1

  • wolfidotnet-bootstrap-8

    < 8.0.129-r0 | < 8.0.130-r0

  • wolfidotnet-bootstrap-9

    < 9.0.120-r0

  • wolfidotnet-sdk-10.0.2

    < 10.0.204-r4

  • wolfidotnet-sdk-10.0.3

    < 10.0.301-r5

  • wolfipowershell

    < 7.6.4-r1

  • wolfipromitor

    < 2.16.0-r3

  • ubuntudotnet10

    < 10.0.110-10.0.10-0ubuntu1~24.04.1 | < 10.0.110-10.0.10-0ubuntu1~26.04.1

  • ubuntudotnet6

    all

  • ubuntudotnet7

    all

  • ubuntudotnet8

    < 8.0.129-8.0.29-0ubuntu1~22.04.1 | < 8.0.129-8.0.29-0ubuntu1~24.04.1

  • microsoftmicrosoft .net framework 3.5

    ≥ 3.5.0, < 2.0.50727.8983 & 3.0.30729.8978

  • microsoftmicrosoft .net framework 3.5 and 4.7.2

    ≥ 4.7.0, < 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0

  • microsoftmicrosoft .net framework 3.5 and 4.8

    ≥ 4.8.0, < 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0

  • microsoftmicrosoft .net framework 3.5 and 4.8.1

    ≥ 4.8.1, < 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0

  • microsoftmicrosoft .net framework 4.6.2/4.7/4.7.1/4.7.2

    ≥ 4.7.0, < 4.7.4143.0

  • microsoftmicrosoft .net framework 4.8

    ≥ 4.8.0, < 4.8.4803.0

  • microsoftmicrosoft .net framework 4.8.1

    ≥ 4.8.0.0, < 4.8.9340.0

  • microsoftmicrosoft visual studio 2017 version 15.9 (includes 15.0 - 15.8)

    -

  • microsoftmicrosoft visual studio 2019 version 16.11 (includes 16.0 - 16.10)

    -

  • microsoftmicrosoft visual studio 2022 version 17.12

    ≥ 17.12.0, < 17.12.22

  • microsoftmicrosoft visual studio 2022 version 17.14

    ≥ 17.14.0, < 17.14.36

  • microsoftmicrosoft visual studio 2026 version 18.5

    -

  • microsoftmicrosoft visual studio 2026 version 18.7

    ≥ 18.0, < 18.7.4

  • microsoft.net

    ≥ 8.0.0, < 8.0.29 | ≥ 9.0.0, < 9.0.18 | ≥ 10.0.0, < 10.0.6

  • microsoft.net 10.0

    ≥ 10.0.0, < 10.0.6 | ≥ 10.0.0, < 10.0.10

  • microsoft.net 8.0

    ≥ 8.0.0, < 8.0.29

  • microsoft.net 9.0

    ≥ 9.0.0, < 9.0.18

  • microsoft.net_framework

    4.8.1 | 4.8 | 4.6.2 | 4.7 | 4.7.1 | 4.7.2 | 3.5

  • microsoftvisual_studio_2017

    ≥ 15.0, ≤ 15.9

  • microsoftvisual_studio_2019

    ≥ 16.0, ≤ 16.11

  • microsoftvisual_studio_2022

    ≥ 17.12.0, < 17.12.22 | ≥ 17.14.0, < 17.14.36

  • microsoftvisual_studio_2026

    ≥ 18.7.0, < 18.7.4 | 18.5.0

  • NuGetSystem.Security.Cryptography.Xml

    ≥ 10.0.0, < 10.0.10 | ≥ 9.0.0, < 9.0.18 | ≥ 8.0.0, < 8.0.4

References (10)