CVE-2026-62898
## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in Microsoft QUIC. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. A use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/426 ## CVSS Details - **Version:** 3.1 - **Severity:** High - **Score:** 7.5 - **Vector:** `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C` - **Weakness:** CWE-416: Use After Free ## Affected Platforms - **Platforms:** Windows - **Architectures:** All ## <a name="affected-packages"></a>Affected Packages The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below ### <a name=".NET 10"></a>.NET 10 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.NETCore.App.Runtime.win-arm64](https://www.nuget.org/packages/Microsoft.NETCore.App.Runtime.win-arm64) | >= 10.0.0, <= 10.0.10 | 10.0.11 [Microsoft.NETCore.App.Runtime.win-x64](https://www.nuget.org/packages/Microsoft.NETCore.App.Runtime.win-x64) | >= 10.0.0, <= 10.0.10 | 10.0.11 [Microsoft.NETCore.App.Runtime.win-x86](https://www.nuget.org/packages/Microsoft.NETCore.App.Runtime.win-x86) | >= 10.0.0, <= 10.0.10 | 10.0.11 ### <a name=".NET 9"></a>.NET 9 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.NETCore.App.Runtime.win-arm64](https://www.nuget.org/packages/Microsoft.NETCore.App.Runtime.win-arm64) | >= 9.0.0, <= 9.0.18 | 9.0.19 [Microsoft.NETCore.App.Runtime.win-x64](https://www.nuget.org/packages/Microsoft.NETCore.App.Runtime.win-x64) | >= 9.0.0, <= 9.0.18 | 9.0.19 [Microsoft.NETCore.App.Runtime.win-x86](https://www.nuget.org/packages/Microsoft.NETCor
Properties
- ghsa_id
- GHSA-c494-m2fq-59mx
- severity
- high
- summary
- Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability
- cvss_score
- 7.5
- cve_id
- CVE-2026-62898
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- is_ghsa_only
- false
- ghsa_published
- 2026-08-11T18:28:37Z
- source_url
- https://github.com/advisories/GHSA-c494-m2fq-59mx
- ghsa_updated
- 2026-08-11T18:34:53Z
Related Entities (8)
VULNERABLE_TO (3)
AFFECTS (3)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph