CVE-2026-34043

high
Published 2026-05-27 Β· Modified 2026-05-27
CVSS v3
β€”
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
8.0

Description

RHSA-2026:21291: .NET 8.0 security update (Important)

Predictions

Exploit likelihood
30%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description serialize-javascript: serialize-javascript: Denial of Service via specially crafted array-like object serialization Red Hat statement Red Hat products in their default configurations do not accept input from unauthenticated users. CVSS v3: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat Enterprise Linux…

Description

serialize-about:blocked: serialize-about:blocked: Denial of Service via specially crafted array-like object serialization

Red Hat statement

Red Hat products in their default configurations do not accept input from unauthenticated users.

CVSS v3: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat Enterprise Linux 10dotnet8.0-0:8.0.127-1.el10_2RHSA-2026:212862026-05-27T00:00:00Z
Red Hat Enterprise Linux 8dotnet8.0-0:8.0.127-1.el8_10RHSA-2026:212912026-05-27T00:00:00Z
Red Hat Enterprise Linux 9dotnet8.0-0:8.0.127-1.el9_8RHSA-2026:212932026-05-27T00:00:00Z
Red Hat OpenShift Container Platform 4.18openshift4/ose-networking-console-plugin-rhel9:1778256287RHSA-2026:174482026-05-20T00:00:00Z
Red Hat OpenShift Container Platform 4.19openshift4/ose-networking-console-plugin-rhel9:1779256322RHSA-2026:200412026-05-27T00:00:00Z
Red Hat OpenShift Container Platform 4.2openshift4/ose-networking-console-plugin-rhel9:1778644858RHSA-2026:174682026-05-20T00:00:00Z
Red Hat OpenShift Container Platform 4.21openshift4/ose-networking-console-plugin-rhel9:1778532500RHSA-2026:174742026-05-19T00:00:00Z

Package state

ProductPackageState
Cryostat 4cryostat-openshift-console-plugin-npmAffected
Cryostat 4serialize-javascriptNot affected
Gatekeeper 3gatekeeper/gatekeeper-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-operator-bundleFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-proxy-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-curator5-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-compat-rhel9Fix deferred
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleFix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorFix deferred
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel9Fix deferred
Red Hat 3scale API Management Platform 23scale-amp20/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp21/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp22/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp24/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp25/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp26/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel7Will not fix
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Will not fix
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel9Affected
Red Hat AMQ Broker 7serialize-javascriptNot affected
Red Hat Ansible Automation Platform 2ansible-on-clouds/aoc-azure-aap-installer-rhel9Affected
Red Hat Ansible Automation Platform 2automation-eda-controllerFix deferred
Red Hat Ansible Automation Platform 2automation-gatewayFix deferred
Red Hat Ansible Automation Platform 2automation-platform-uiAffected
Red Hat build of Apache Camel - HawtIO 4serialize-javascriptAffected
Red Hat build of Apicurio Registry 2serialize-javascriptFix deferred
Red Hat Build of Keycloakserialize-javascriptWill not fix
Red Hat Build of Podman Desktoppodman-desktop-macos-1-0Affected
Red Hat Build of Podman Desktoppodman-desktop-windows-1-0Affected
Red Hat Data Grid 8serialize-javascriptNot affected
Red Hat Enterprise Linux 8grafanaAffected
Red Hat Enterprise Linux 8pcsNot affected
Red Hat Enterprise Linux 9dotnet6.0Not affected
Red Hat Enterprise Linux 9dotnet7.0Not affected
Red Hat Enterprise Linux 9grafanaAffected
Red Hat Enterprise Linux 9pcsNot affected
Red Hat Fuse 7serialize-javascriptFix deferred
Red Hat JBoss Enterprise Application Platform 8serialize-javascriptNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packserialize-javascriptNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-console-rhel9Affected
Red Hat OpenShift Container Platform 4openshift4/ose-monitoring-plugin-rhel9Affected
Red Hat Openshift Data Foundation 4odf4/ocs-client-console-rhel9Fix deferred
Red Hat Openshift Data Foundation 4odf4/odf-console-rhel9Fix deferred
Red Hat Openshift Data Foundation 4odf4/odf-multicluster-console-rhel9Fix deferred
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel8Affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel9Affected
Red Hat OpenShift Virtualization 4container-native-virtualization/kubevirt-console-plugin-rhel9Fix deferred
Red Hat Process Automation 7serialize-javascriptFix deferred
Red Hat Quay 3quay/quay-rhel8Fix deferred
Red Hat Satellite 6nodejs-compression-webpack-pluginNot affected
Red Hat Satellite 6nodejs-webpackNot affected
Red Hat Single Sign-On 7serialize-javascriptFix deferred
streams for Apache Kafka 2serialize-javascriptFix deferred
streams for Apache Kafka 3serialize-javascriptNot affected

Apply commands

bash fix
Apply RHSA-2026:21286 for Red Hat Enterprise Linux 10
yum update -y dotnet8
# or:
dnf upgrade -y dotnet8

Affected

VendorProductVersion
redhatCryostat 4Affected
redhatCryostat 4Not affected
redhatGatekeeper 3Not affected
redhatRed Hat 3scale API Management Platform 2Affected
redhatRed Hat AMQ Broker 7Not affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat Ansible Automation Platform 2Affected
redhatRed Hat build of Apache Camel - HawtIO 4Affected
redhatRed Hat Build of Podman DesktopAffected
redhatRed Hat Build of Podman DesktopAffected
redhatRed Hat Data Grid 8Not affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat JBoss Enterprise Application Platform 8Not affected
redhatRed Hat JBoss Enterprise Application Platform Expansion PackNot affected
redhatRed Hat OpenShift Container Platform 4Affected
redhatRed Hat OpenShift Container Platform 4Affected
redhatRed Hat OpenShift GitOpsAffected
redhatRed Hat OpenShift GitOpsAffected
redhatRed Hat Satellite 6Not affected
redhatRed Hat Satellite 6Not affected
redhatstreams for Apache Kafka 3Not affected

OS impact

debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected β€”
sid Fixed 7.0.5+~5.0.4-1
forky Fixed 7.0.5+~5.0.4-1
bullseye Affected β€”
bookworm Affected β€”
almalinux AlmaLinux Fixed 2 releases
VersionStatusFixed in
9 Fixed aspnetcore-runtime-dbg-8.0-8.0.27-1.el9_8.aarch64.rpm
8 Fixed dotnet-sdk-8.0-source-built-artifacts-8.0.127-1.el8_10.x86_64.rpm
redhat Red Hat Fixed 2 releases
VersionStatusFixed in
9 Fixed β€”
8 Fixed β€”

Package impact

EcosystemPackageVulnerableFixed
npm npmserialize-javascript>=5.0.0,<7.0.57.0.5
npm NPMserialize-javascript>= 5.0.0, < 7.0.57.0.5

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.