© 2026 Hedgehog Software, LLC

TwitterGitHubDiscord
More
CommunitiesDocsAboutTermsPrivacy
Search
Star
Setup for Free
C#C
C#•2y ago•
13 replies
HokiePokeDad

✅ .NET 8 CVE-2024-38167 and updating project references

I'm stuck between a rock and a hard place here. The majority of our applications and projects are typically up-to-date when the latest patches for .NET 8 and other dependencies in NuGet. Our vulnerability scanner is reporting the versions of various assemblies referenced, in this case System.Text.Json.dll, are vulnerable due to CVE-2024-38167 (https://nvd.nist.gov/vuln/detail/CVE-2024-38167). The published CVE notes that the latest non-vulnerable version is 8.0.8; however, the latest publicly released version is 8.0.4, with a few pre-release versions. When published, our projects show a version of 8.0.7. How would I go about upgrading to 8.0.8 if it's not available via NuGet?
C# banner
C#Join
We are a programming server aimed at coders discussing everything related to C# (CSharp) and .NET.
61,871Members
Resources

Similar Threads

Was this page helpful?
Recent Announcements

Similar Threads

Issues Updating Hybrid .NET MAUI Project from .NET 7 to .NET 8 with Xcode 16 and macOS Updates
C#CC# / help
16mo ago
Mixed Project References
C#CC# / help
2y ago
✅ Error while Dockerizing an ASP.NET project which references another project.
C#CC# / help
2y ago
NuGet package project references
C#CC# / help
17mo ago