/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-xr48-wrc7-9wmf

Published

Last updated

https://images.chainguard.dev/security/CGA-xr48-wrc7-9wmf
Package

dotnet-9

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2025-26646
  • GHSA-h4j7-5rxr-p4wc

Severity

8.0

High

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-26646

Updates

Status

Not affected

Justification

Component not present

Impact

Currently the scanners are detecting that the package has version of Microsoft.Build.Tasks.Core '17.3.4' installed. The scanners are currently not reporting the dll version installed which is the code that gets executed as per: https://github.com/dotnet/msbuild/issues/11846\#issuecomment-2883242143 Currently /usr/share/dotnet/sdk/9.0.106/Microsoft.Build.Tasks.Core.dll is at version 17.12.35 which is not a vulnerable version as per the CVE advisory.


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing