Aug 12, 2026·6 min read·147 visits
A medium-severity HTTP request smuggling vulnerability in .NET on Linux and macOS allows unauthenticated remote attackers to bypass frontend security policies, hijack active user sessions, and cause cache desynchronization.
CVE-2026-62899 is a security feature bypass vulnerability in the Microsoft .NET runtime environment on non-Windows platforms. The flaw manifests as an HTTP Request/Response Smuggling vulnerability (CWE-444) within the managed implementation of the System.Net.HttpListener class. This allows unauthenticated remote attackers to desynchronize request boundaries when the backend .NET application is hosted behind an upstream reverse proxy.
CVE-2026-62899 represents a security feature bypass vulnerability in the Microsoft .NET runtime environment on non-Windows platforms. The flaw arises from an HTTP Request/Response Smuggling vulnerability, classified as CWE-444, within the managed implementation of the System.Net.HttpListener class.
While Windows implementations delegate HTTP parsing to the robust, kernel-level http.sys driver, non-Windows systems (including Linux and macOS) rely on a custom, managed C# HTTP parser. This architectural difference introduces discrepancies in how HTTP request boundaries are parsed and validated compared to upstream reverse proxies like Nginx or HAProxy.
An unauthenticated remote attacker can exploit these parsing inconsistencies to desynchronize the connection boundaries between the reverse proxy and the backend .NET server. This desynchronization enables the attacker to inject a hidden secondary request within the body of a primary request, leading to security control bypasses or unauthorized data exposure.
The root cause of CVE-2026-62899 lies in inconsistent parsing logic and character normalization routines inside the managed C# HTTP parser of System.Net.HttpListener. When the parser processes incoming headers, it handles whitespaces and character normalization in an overly permissive manner, deviating from strict RFC standards.
Specifically, the managed parser's integration with ICU (International Components for Unicode) globalization libraries created a normalization vulnerability. If HTTP headers are validated using culture-aware string methods rather than strict, binary-level ordinal checks, certain full-width Unicode characters can be normalized into standard ASCII control characters like colons or line endings. This allows an attacker to construct headers that appear benign to an upstream proxy but are interpreted as structural boundaries by the backend .NET runtime.
Furthermore, the parser failed to strictly enforce RFC 9112 rules regarding trailing and leading whitespaces in header fields, particularly around the colon delimiter. The permissive handling of malformed headers (such as Transfer-Encoding : chunked) allows an attacker to cause a desynchronization where the frontend proxy ignores the header due to strict validation, while the backend processes it, or vice versa.
The remediation of this vulnerability required updating key parsing components and upgrading native and managed dependencies within the .NET runtime. Developers resolved the ICU normalization issue by enforcing strict ASCII/ordinal string comparisons on all HTTP header fields, preventing Unicode normalization side-channels.
In addition, native transport libraries were upgraded to enforce stricter boundary validation. The native MsQuic library was bumped from version 2.4.18 to 2.5.9 within the eng/Versions.props file to resolve potential state machine issues in HTTP/3 transport processing. The following diff highlights the dependency transitions implemented in the servicing branch:
<!-- eng/Versions.props -->
<Project>
<PropertyGroup>
- <MicrosoftNativeQuicMsQuicSchannelVersion>2.4.18</MicrosoftNativeQuicMsQuicSchannelVersion>
+ <MicrosoftNativeQuicMsQuicSchannelVersion>2.5.9</MicrosoftNativeQuicMsQuicSchannelVersion>
</PropertyGroup>
</Project>The Microsoft.NETCore.Runtime.ICU.Transport package was also updated across multiple cycles to secure the globalization boundary. Specifically, the package version was rolled from 10.0.0-rtm.26313.1 to 10.0.0-rtm.26364.2 to eliminate character-mapping discrepancies.
Exploiting CVE-2026-62899 requires a deployment scenario where the backend .NET application is hosted on Linux or macOS behind an affected frontend reverse proxy. The attacker targets the connection state using standard HTTP Request Smuggling vectors, such as CL.TE or TE.CL.
In a CL.TE scenario, the attacker transmits a single TCP payload containing a standard Content-Length header and a malformed Transfer-Encoding : chunked header with a trailing whitespace. The frontend proxy, validating strictly, reads the request according to the Content-Length field and forwards the entire stream. The backend .NET parser, being overly permissive, normalizes the malformed Transfer-Encoding header and treats the body as chunked data.
When the backend server encounters the terminating chunk (0), it concludes the processing of the first request. The remaining bytes in the connection buffer are then parsed as a new, separate HTTP request. This secondary, smuggled request executes in the context of the established TCP connection, bypassing access lists enforced by the frontend proxy.
The impact of a successful HTTP request smuggling exploit is classified as high for confidentiality. An attacker who successfully desynchronizes a persistent connection can intercept and manipulate the requests and responses of other users sharing that connection.
This capability allows the attacker to hijack active sessions by capturing sensitive headers, authorization tokens, or session cookies. Additionally, if a caching proxy is utilized in the architecture, the attacker can execute web cache poisoning attacks, storing malicious responses on the proxy to be served to subsequent legitimate users.
From a CVSS perspective, the vulnerability receives a base score of 5.9 (Medium). The score reflects high confidentiality impact but zero direct integrity or availability impact because the vulnerability does not natively permit code execution or persistent data modification. However, the downstream impact of session hijacking can lead to complete application compromise.
Resolving CVE-2026-62899 requires updating the .NET SDK and runtime to the latest patched servicing releases. Organizations running applications on Linux or macOS must upgrade to .NET 10.0.11, .NET 9.0.19, or .NET 8.0.30 immediately to receive the secure HTTP parser implementation.
Where immediate patching of the runtime is unfeasible, several mitigating controls can be implemented. Administrators should configure their frontend reverse proxies (such as Nginx or HAProxy) to normalize incoming HTTP headers strictly, ensuring that requests containing conflicting framing or non-standard whitespaces are rejected before reaching the backend.
Alternatively, disabling connection keep-alives at the reverse proxy or backend level will mitigate the threat of smuggling by forcing the termination of the TCP connection after each request. However, this mitigation is not recommended as a long-term solution because it introduces significant latency and processing overhead due to repeated TCP handshakes.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C| Product | Affected Versions | Fixed Version |
|---|---|---|
Microsoft .NET 10.0 Microsoft | >= 10.0.0, < 10.0.11 | 10.0.11 |
Microsoft .NET 9.0 Microsoft | >= 9.0.0, < 9.0.19 | 9.0.19 |
Microsoft .NET 8.0 Microsoft | >= 8.0.0, < 8.0.30 | 8.0.30 |
Microsoft Visual Studio 2022 (version 17.14) Microsoft | >= 17.14.0, < 17.14.38 | 17.14.38 |
Microsoft Visual Studio 2026 (version 18.8) Microsoft | >= 18.0, < 18.8.3 | 18.8.3 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-444 |
| Attack Vector | Network (AV:N) |
| Attack Complexity | High (AC:H) |
| CVSS Base Score | 5.9 (Medium) |
| Exploit Status | No active public exploits |
| KEV Status | Not Listed |
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
An Improper Access Control vulnerability (CWE-284) in Payload CMS prior to version 3.90.0 and 4.0.0-canary.34 allows authenticated, low-privileged users to bypass field-level access control restrictions and overwrite the password of other accounts, leading to complete account takeover and privilege escalation.
Payload CMS was discovered to use an insecure default configuration for its password-hashing mechanism. The system requested a 512-byte key from PBKDF2-HMAC-SHA256 with 25,000 iterations, creating a severe cryptographic asymmetry. While the defending server sequentially computed 16 blocks of key material (equivalent to 400,000 internal iterations), an offline attacker only needed to compute the first 32-byte block to verify password guesses. This allowed offline attackers to crack stolen database hashes 16 times faster than intended by the security design.
VectorFreed identifies a critical Use-After-Free (UAF) memory corruption vulnerability in librsvg (CVE-2026-96889), which manifests when parsing structured SVG documents containing nested XML inclusions (XIncludes) and duplicate entity declarations. The flaw results from an entity ownership conflict where librsvg prematurely deallocates an xmlEntity structure still actively referenced by the underlying libxml2 parser context. When transitively compiled into downstream applications such as the high-performance sharp image processing library, this vulnerability facilitates denial of service and unauthenticated remote code execution on the host operating system.
CVE-2026-102275 (GHSA-x33g-cr3x-6449) is a public/private key identity confusion vulnerability in PyJWT versions 2.1.0 through 2.14.0. When importing Octet Key Pair (OKP) JSON Web Keys (JWKs) representing Ed25519 or Ed448 curves, PyJWT fails to verify that the public parameter 'x' matches the private parameter 'd'. An attacker can construct a hybrid JWK combining a victim's public key with the attacker's private key. In protocols like DPoP that bind sessions via public key thumbprints, this allows the attacker to authenticate as the victim while signing proofs with their own private key, fully bypassing sender-constrained security guarantees.
An authentication bypass and privilege escalation vulnerability exists in Filament (filamentphp/filament) due to missing password verification during multi-factor authentication (MFA) setup and management. An attacker with access to an active session can modify or disable MFA, leading to account hijacking.
A critical Denial of Service (DoS) vulnerability exists in @socket.io/cluster-engine before version 0.1.1. Unauthenticated remote attackers can crash the server process by supplying inherited prototype property names as session identifiers.