CVE-2026-105444 | dotnet eShop .NET 8 Ordering API OrdersApi.cs GetOrderAsync OrderNumber resource injection (Issue 996)
A vulnerability was found in dotnet eShop .NET 8. It has been classified as critical. The impacted element is the function GetOrderAsync of the file src/Ordering.API/Apis/OrdersApi.cs of the component Ordering API. Performing a manipulation of the argument OrderNumber results in improper control of resource identifiers.
This vulnerability is reported as CVE-2026-105444. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More