Shared Framework for hosting of Microsoft ASP.NET Core applications. It is open source, cross-platform and is supported by Microsoft. We hope you enjoy using it! If you do, please consider joining the active community of developers that are contributing to the project on GitHub (https://github.com/dotnet/dotnet). We happily accept issues and PRs.
Microsoft.AspNetCore.App.Runtime.linux-arm64 has critical vulnerabilities — do not use
Update to >= 6.0.2 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | BIT-aspnet-core-2020-0602 | Denial of service in ASP.NET Core | 3.1.1 |
| high | BIT-aspnet-core-2021-1723 | ASP.NET Core and Visual Studio Denial of Service Vulnerability | 5.0.2 |
| high | BIT-dotnet-2023-33170 | Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability | 6.0.20 |
| high | BIT-aspnet-core-2025-24070 | Microsoft Security Advisory CVE-2025-24070: .NET Elevation of Privilege Vulnerability | 9.0.3 |
| high | BIT-aspnet-core-2020-1161 | ASP.NET Core Denial of Service Vulnerability | 3.1.4 |
| high | BIT-dotnet-2022-29117 | .NET Denial of Service Vulnerability | 6.0.5 |
| high | BIT-dotnet-2022-23267 | .NET Denial of Service Vulnerability | 6.0.5 |
| high | BIT-aspnet-core-2026-26130 | .NET Denial of Service Vulnerability | 10.0.4 |
| critical | BIT-aspnet-core-2025-55315 | Microsoft Security Advisory CVE-2025-55315: .NET Security Feature Bypass Vulnerability | 8.0.21 |
| high | BIT-aspnet-core-2020-0603 | Remote code execution in ASP.NET Core | 3.1.1 |
| high | BIT-dotnet-2024-38229 | Microsoft Security Advisory CVE-2024-38229 | .NET Remote Code Execution Vulnerability | 8.0.10 |
| critical | BIT-dotnet-2024-35264 | Microsoft Security Advisory CVE-2024-35264 | .NET Remote Code Execution Vulnerability | 8.0.7 |
| high | BIT-dotnet-2022-24464 | .NET Denial of Service Vulnerability | 6.0.3 |
| high | BIT-aspnet-core-2020-1597 | ASP.NET Core Denial of Service Vulnerability | 3.1.7 |
| high | BIT-dotnet-2022-29145 | .NET Denial of Service Vulnerability | 6.0.5 |
| high | BIT-aspnet-core-2024-21386 | Microsoft Security Advisory CVE-2024-21386: .NET Denial of Service Vulnerability | 8.0.2 |
| medium | BIT-dotnet-2024-30046 | Microsoft Security Advisory CVE-2024-30046 | .NET Denial of Service Vulnerability | 8.0.5 |
| high | BIT-aspnet-core-2020-1045 | Cookie parsing failure | 3.1.8 |
| high | BIT-dotnet-2022-38013 | .NET Denial of Service Vulnerability | 6.0.9 |
| medium | BIT-dotnet-2022-34716 | .NET Information Disclosure Vulnerability | 6.0.8 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/nuget/Microsoft.AspNetCore.App.Runtime.linux-arm64Last updated · 2026-04-14T16:00:01.16+00:00