More information about this security flaw is available in the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=2292777 Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Based on https://nvd.nist.gov/vuln/detail/cve-2024-37890, the fix is to update to ws.10. ASP.NET Core made that change in https://github.com/dotnet/aspnetcore/commit/baf82a19604e265a78ccbb6689be813cc9a0f3fc. That was released with .NET 8.0.10, which was made public in October 2024. .NET 8.0.110/8.0.10 was released for Fedora in 2024: - Fedora 39: https://bodhi.fedoraproject.org/updates/FEDORA-2024-180560c54b - Fedora 40: https://bodhi.fedoraproject.org/updates/FEDORA-2024-204d982a2e - Fedora 41: https://bodhi.fedoraproject.org/updates/FEDORA-2024-cc3d21b83b - Fedora 42: https://bodhi.fedoraproject.org/updates/FEDORA-2024-bfe334b47a