CVE-2023-35391: Microsoft .net
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
Affected products
- Microsoft .net: from 6.0.0, before 6.0.21 (fixed in 6.0.21); from 7.0.0, before 7.0.10 (fixed in 7.0.10)
- Microsoft ASP.NET Core: from 2.1, before 2.1.40 (fixed in 2.1.40)
- Microsoft Visual Studio 2022: from 17.2.0, before 17.2.18 (fixed in 17.2.18); from 17.4.0, before 17.4.10 (fixed in 17.4.10); from 17.6.0, before 17.6.6 (fixed in 17.6.6)
Published 2023-08-08. Last modified 2026-08-10.