CVE-2025-26646
HighAdvisory
Published 13 May 2025In the index since 8 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.0
- base score, highest
- EPSS
- 0.012
- 66th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2
- of 17,781 indexed, latest versions
- Container images
- 4
- deployed by those charts
- Fix available
- 3 of 4
- affected packages
Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability
Carried by container images the latest versions of 2 of 17,781 indexed charts deploy, on 4 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| Microsoft.Build.Tasks.Corenuget | 17.8.5, 17.11.22 | 17.8.29, 17.12.36 | 4 |
| dotnet8.0rpm | 8.0.12-1.el8_10 | 0:8.0.16-1.el8_10 | 3 |
| dotnet9.0rpm | 9.0.1-1.el8_10 | 0:9.0.5-1.el8_10 | 3 |
| dotnet6deb | 6.0.136-0ubuntu1~22.04.1 | no fix listed | 1 |
- OSV records
- GHSA-h4j7-5rxr-p4wcRHSA-2025:7571RHSA-2025:7589UBUNTU-CVE-2025-26646
- Also known as
- BIT-dotnet-2025-26646, BIT-dotnet-sdk-2025-26646
Charts affected
2 by stars
Container images carrying it
4 by charts deploying them
A fixed version is listed for 3 of the 4 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ryuunosukeds3/ | c0398f13e8a9 | dotnet6 Microsoft.Build.Tasks.Core | no fix listed 17.12.36 | 1 |
| quay.io/ | b596a4687bb0 | dotnet8.0 dotnet9.0 Microsoft.Build.Tasks.Core | 0:8.0.16-1.el8_10 0:9.0.5-1.el8_10 17.8.29 | 1 |
| quay.io/ | d50c80a85b35 | dotnet8.0 dotnet9.0 Microsoft.Build.Tasks.Core | 0:8.0.16-1.el8_10 0:9.0.5-1.el8_10 17.8.29 | 1 |
| quay.io/ | f9c71dc2bc5f | dotnet8.0 dotnet9.0 Microsoft.Build.Tasks.Core | 0:8.0.16-1.el8_10 0:9.0.5-1.el8_10 17.8.29 | 1 |