Loading HuntDB...

GHSA-ghhp-997w-qr28

GitHub Security Advisory

.NET Core Remote Code Execution Vulnerability

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

.NET Core Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24112.

### Executive summary

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1, and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A remote code execution vulnerability exists in .NET 5 and .NET Core due to how text encoding is performed.

### Discussion

Discussion for this issue can be found at dotnet/runtime#49377

### Mitigation factors

Microsoft has not identified any mitigating factors for this vulnerability.

### Affected software

The vulnerable package is `System.Text.Encodings.Web` . Upgrading your package and redeploying your app should be sufficient to address this vulnerability.

Vulnerable package versions:

Any .NET 5, .NET Core, or .NET Framework based application that uses the System.Text.Encodings.Web package with a vulnerable version listed below.

Package Name | Vulnerable Versions | Secure Versions
-|-|-
System.Text.Encodings.Web | 4.0.0 - 4.5.0 | 4.5.1
System.Text.Encodings.Web | 4.6.0-4.7.1 | 4.7.2
System.Text.Encodings.Web | 5.0.0 | 5.0.1

Please validate that each of the .NET versions you are using is in support. Security updates are only provided for supported .NET versions.

Affected Packages

NuGet System.Text.Encodings.Web
Affected versions: 4.0.0 (fixed in 4.5.1)
NuGet System.Text.Encodings.Web
Affected versions: 4.6.0 (fixed in 4.7.2)
NuGet System.Text.Encodings.Web
Affected versions: 5.0.0 (fixed in 5.0.1)

Related CVEs

Key Information

GHSA ID
GHSA-ghhp-997w-qr28
Published
April 21, 2021 7:38 PM
Last Modified
April 21, 2021 7:37 PM
CVSS Score
9.0 /10
Primary Ecosystem
NuGet
Primary Package
System.Text.Encodings.Web
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.