Bug 2528870 (CVE-2026-58649)

Summary: CVE-2026-58649 dotnet10.0: dotnet9.0: dotnet8.0: .NET Information Disclosure Vulnerability
Product: [Other] Security Response Reporter: Charles Timko <ctimko>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: rhel-process-autobot, security-response-team, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
dotnet watch BrowserRefreshServer does not adequately validate cross-origin WebSocket origins, potentially allowing IL and PDB information disclosure.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2530879, 2530880, 2530881    
Bug Blocks:    
Deadline: 2026-09-08   

Description Charles Timko 2026-09-04 19:54:47 UTC
dotnet watch BrowserRefreshServer does not adequately validate cross-origin WebSocket origins, potentially allowing IL and PDB information disclosure.

CNA: microsoft
CNA impact: Information Disclosure
CWE: CWE-346
Platforms: all
Architectures: all
CVSS 3.1: 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)

Affected packages:
- dotnet-sdk (release 10.0): 10.0.400 - 10.0.400; fixed 10.0.401 [dotnet@ae39133]
- dotnet-sdk (release 9.0): 9.0.300 - 9.0.317; fixed 9.0.318 [sdk@d78666e]
- dotnet-sdk (release 10.0): 10.0.100 - 10.0.111; fixed 10.0.112 [dotnet@882ef16]
- dotnet-sdk (release 8.0): 8.0.100 - 8.0.130; fixed 8.0.131 [sdk@de67b09]
- dotnet-sdk (release 8.0): 8.0.400 - 8.0.424; fixed 8.0.425 [sdk@71ec990]
- dotnet-sdk (release 9.0): 9.0.100 - 9.0.120; fixed 9.0.121 [sdk@97124d7]

Fix commits:
- dotnet/dotnet (release/10.0.4xx): https://github.com/dotnet/dotnet/commit/ae39133877be792de27db50aaf415b5e9f003e11
- dotnet/sdk (release/9.0.3xx): https://github.com/dotnet/sdk/commit/d78666eeb83defc38c76bdf36f57a9a37b8e6e2a
- dotnet/dotnet (release/10.0.1xx): https://github.com/dotnet/dotnet/commit/882ef164b92836bf0cabcf8eb8719274e9dc075e
- dotnet/sdk (release/8.0.1xx): https://github.com/dotnet/sdk/commit/de67b096e71fd0df5ebe2cfd517270651f9f8ef6
- dotnet/sdk (release/8.0.4xx): https://github.com/dotnet/sdk/commit/71ec9905155a8271ee90d42c20aaa54b9425f4ae
- dotnet/sdk (release/9.0.1xx): https://github.com/dotnet/sdk/commit/97124d73362451fe8c40ab5dbaab3396908029cb

Comment 1 Jon Orris 2026-09-15 11:20:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:67525 https://access.redhat.com/errata/RHSA-2026:67525

Comment 2 Jon Orris 2026-09-15 11:47:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:67524 https://access.redhat.com/errata/RHSA-2026:67524

Comment 3 Jon Orris 2026-09-15 12:02:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:67528 https://access.redhat.com/errata/RHSA-2026:67528

Comment 4 Jon Orris 2026-09-15 12:03:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:67530 https://access.redhat.com/errata/RHSA-2026:67530

Comment 5 Jon Orris 2026-09-15 20:02:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:67614 https://access.redhat.com/errata/RHSA-2026:67614

Comment 6 Jon Orris 2026-09-15 20:05:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:67613 https://access.redhat.com/errata/RHSA-2026:67613

Comment 7 Jon Orris 2026-09-16 15:56:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:68233 https://access.redhat.com/errata/RHSA-2026:68233

Comment 8 Jon Orris 2026-09-16 17:41:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:68316 https://access.redhat.com/errata/RHSA-2026:68316

Comment 9 Jon Orris 2026-09-17 14:33:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:68676 https://access.redhat.com/errata/RHSA-2026:68676