Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
RHSA-2026:41896
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:41896
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:41896.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2026:41896
Upstream
CVE-2026-47300
CVE-2026-47302
CVE-2026-47303
CVE-2026-47304
CVE-2026-50524
CVE-2026-50525
CVE-2026-50526
CVE-2026-50527
CVE-2026-50528
CVE-2026-50646
CVE-2026-50648
CVE-2026-50649
CVE-2026-50650
CVE-2026-50651
CVE-2026-50659
CVE-2026-56170
CVE-2026-57108
Published
2026-07-23T10:13:40Z
Modified
2026-07-23T10:32:27.827215961Z
Severity
8.8 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: .NET 9.0 security, bug fix, and enhancement update
Details
References
https://access.redhat.com/errata/RHSA-2026:41896
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=2499217
https://bugzilla.redhat.com/show_bug.cgi?id=2500109
https://bugzilla.redhat.com/show_bug.cgi?id=2500189
https://bugzilla.redhat.com/show_bug.cgi?id=2500492
https://bugzilla.redhat.com/show_bug.cgi?id=2500502
https://bugzilla.redhat.com/show_bug.cgi?id=2500509
https://bugzilla.redhat.com/show_bug.cgi?id=2500515
https://bugzilla.redhat.com/show_bug.cgi?id=2500556
https://bugzilla.redhat.com/show_bug.cgi?id=2500562
https://bugzilla.redhat.com/show_bug.cgi?id=2500563
https://bugzilla.redhat.com/show_bug.cgi?id=2500565
https://bugzilla.redhat.com/show_bug.cgi?id=2500577
https://bugzilla.redhat.com/show_bug.cgi?id=2500580
https://bugzilla.redhat.com/show_bug.cgi?id=2500581
https://bugzilla.redhat.com/show_bug.cgi?id=2500587
https://bugzilla.redhat.com/show_bug.cgi?id=2500589
https://bugzilla.redhat.com/show_bug.cgi?id=2500593
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_41896.json
https://access.redhat.com/security/cve/CVE-2026-47300
https://www.cve.org/CVERecord?id=CVE-2026-47300
https://nvd.nist.gov/vuln/detail/CVE-2026-47300
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47300
https://access.redhat.com/security/cve/CVE-2026-47302
https://www.cve.org/CVERecord?id=CVE-2026-47302
https://nvd.nist.gov/vuln/detail/CVE-2026-47302
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47302
https://access.redhat.com/security/cve/CVE-2026-47303
https://www.cve.org/CVERecord?id=CVE-2026-47303
https://nvd.nist.gov/vuln/detail/CVE-2026-47303
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47303
https://access.redhat.com/security/cve/CVE-2026-47304
https://www.cve.org/CVERecord?id=CVE-2026-47304
https://nvd.nist.gov/vuln/detail/CVE-2026-47304
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47304
https://access.redhat.com/security/cve/CVE-2026-50524
https://www.cve.org/CVERecord?id=CVE-2026-50524
https://nvd.nist.gov/vuln/detail/CVE-2026-50524
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50524
https://access.redhat.com/security/cve/CVE-2026-50525
https://www.cve.org/CVERecord?id=CVE-2026-50525
https://nvd.nist.gov/vuln/detail/CVE-2026-50525
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50525
https://access.redhat.com/security/cve/CVE-2026-50526
https://www.cve.org/CVERecord?id=CVE-2026-50526
https://nvd.nist.gov/vuln/detail/CVE-2026-50526
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50526
https://access.redhat.com/security/cve/CVE-2026-50527
https://www.cve.org/CVERecord?id=CVE-2026-50527
https://nvd.nist.gov/vuln/detail/CVE-2026-50527
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50527
https://access.redhat.com/security/cve/CVE-2026-50528
https://www.cve.org/CVERecord?id=CVE-2026-50528
https://nvd.nist.gov/vuln/detail/CVE-2026-50528
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50528
https://access.redhat.com/security/cve/CVE-2026-50646
https://www.cve.org/CVERecord?id=CVE-2026-50646
https://nvd.nist.gov/vuln/detail/CVE-2026-50646
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50646
https://access.redhat.com/security/cve/CVE-2026-50648
https://www.cve.org/CVERecord?id=CVE-2026-50648
https://nvd.nist.gov/vuln/detail/CVE-2026-50648
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50648
https://access.redhat.com/security/cve/CVE-2026-50649
https://www.cve.org/CVERecord?id=CVE-2026-50649
https://nvd.nist.gov/vuln/detail/CVE-2026-50649
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50649
https://access.redhat.com/security/cve/CVE-2026-50650
https://www.cve.org/CVERecord?id=CVE-2026-50650
https://nvd.nist.gov/vuln/detail/CVE-2026-50650
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50650
https://access.redhat.com/security/cve/CVE-2026-50651
https://www.cve.org/CVERecord?id=CVE-2026-50651
https://nvd.nist.gov/vuln/detail/CVE-2026-50651
https://access.redhat.com/security/cve/CVE-2026-50659
https://www.cve.org/CVERecord?id=CVE-2026-50659
https://nvd.nist.gov/vuln/detail/CVE-2026-50659
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50659
https://access.redhat.com/security/cve/CVE-2026-56170
https://www.cve.org/CVERecord?id=CVE-2026-56170
https://nvd.nist.gov/vuln/detail/CVE-2026-56170
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56170
https://access.redhat.com/security/cve/CVE-2026-57108
https://www.cve.org/CVERecord?id=CVE-2026-57108
https://nvd.nist.gov/vuln/detail/CVE-2026-57108
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57108
Affected packages
Red Hat:enterprise_linux:9::appstream
aspnetcore-runtime-9.0
Package
Name
aspnetcore-runtime-9.0
Purl
pkg:rpm/redhat/aspnetcore-runtime-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
aspnetcore-runtime-dbg-9.0
Package
Name
aspnetcore-runtime-dbg-9.0
Purl
pkg:rpm/redhat/aspnetcore-runtime-dbg-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
aspnetcore-targeting-pack-9.0
Package
Name
aspnetcore-targeting-pack-9.0
Purl
pkg:rpm/redhat/aspnetcore-targeting-pack-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-apphost-pack-9.0
Package
Name
dotnet-apphost-pack-9.0
Purl
pkg:rpm/redhat/dotnet-apphost-pack-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-apphost-pack-9.0-debuginfo
Package
Name
dotnet-apphost-pack-9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet-apphost-pack-9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-hostfxr-9.0
Package
Name
dotnet-hostfxr-9.0
Purl
pkg:rpm/redhat/dotnet-hostfxr-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-hostfxr-9.0-debuginfo
Package
Name
dotnet-hostfxr-9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet-hostfxr-9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-runtime-9.0
Package
Name
dotnet-runtime-9.0
Purl
pkg:rpm/redhat/dotnet-runtime-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-runtime-9.0-debuginfo
Package
Name
dotnet-runtime-9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet-runtime-9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-runtime-dbg-9.0
Package
Name
dotnet-runtime-dbg-9.0
Purl
pkg:rpm/redhat/dotnet-runtime-dbg-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-sdk-9.0
Package
Name
dotnet-sdk-9.0
Purl
pkg:rpm/redhat/dotnet-sdk-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-sdk-9.0-debuginfo
Package
Name
dotnet-sdk-9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet-sdk-9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-sdk-aot-9.0
Package
Name
dotnet-sdk-aot-9.0
Purl
pkg:rpm/redhat/dotnet-sdk-aot-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-sdk-aot-9.0-debuginfo
Package
Name
dotnet-sdk-aot-9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet-sdk-aot-9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-sdk-dbg-9.0
Package
Name
dotnet-sdk-dbg-9.0
Purl
pkg:rpm/redhat/dotnet-sdk-dbg-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-targeting-pack-9.0
Package
Name
dotnet-targeting-pack-9.0
Purl
pkg:rpm/redhat/dotnet-targeting-pack-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-templates-9.0
Package
Name
dotnet-templates-9.0
Purl
pkg:rpm/redhat/dotnet-templates-9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet9.0
Package
Name
dotnet9.0
Purl
pkg:rpm/redhat/dotnet9.0
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet9.0-debuginfo
Package
Name
dotnet9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet9.0-debugsource
Package
Name
dotnet9.0-debugsource
Purl
pkg:rpm/redhat/dotnet9.0-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
netstandard-targeting-pack-2.1
Package
Name
netstandard-targeting-pack-2.1
Purl
pkg:rpm/redhat/netstandard-targeting-pack-2.1
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
Red Hat:enterprise_linux:9::crb
dotnet-apphost-pack-9.0-debuginfo
Package
Name
dotnet-apphost-pack-9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet-apphost-pack-9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-hostfxr-9.0-debuginfo
Package
Name
dotnet-hostfxr-9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet-hostfxr-9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-runtime-9.0-debuginfo
Package
Name
dotnet-runtime-9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet-runtime-9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.18-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-sdk-9.0-debuginfo
Package
Name
dotnet-sdk-9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet-sdk-9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-sdk-9.0-source-built-artifacts
Package
Name
dotnet-sdk-9.0-source-built-artifacts
Purl
pkg:rpm/redhat/dotnet-sdk-9.0-source-built-artifacts
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet-sdk-aot-9.0-debuginfo
Package
Name
dotnet-sdk-aot-9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet-sdk-aot-9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet9.0-debuginfo
Package
Name
dotnet9.0-debuginfo
Purl
pkg:rpm/redhat/dotnet9.0-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
dotnet9.0-debugsource
Package
Name
dotnet9.0-debugsource
Purl
pkg:rpm/redhat/dotnet9.0-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
0:9.0.119-1.el9_8
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:41896.json"
RHSA-2026:41896 - OSV