CVE-2026-32178
Analyzed
Analyzed - Analysis Complete
NET Spoofing Vulnerability via Improper Input Neutralization
Publication date: 2026-04-14
Last updated on: 2026-05-07
Assigner: Microsoft Corporation
Description
Description
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | .net | From 10.0.0 (inc) to 10.0.6 (exc) |
| microsoft | .net | From 8.0.0 (inc) to 8.0.26 (exc) |
| microsoft | .net | From 9.0.0 (inc) to 9.0.15 (exc) |
| microsoft | visual_studio_2022 | From 17.12.0 (inc) to 17.12.19 (exc) |
| microsoft | visual_studio_2022 | From 17.14.0 (inc) to 17.14.30 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-138 | The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as control elements or syntactic markers when they are sent to a downstream component. |