Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NETSDK1238 warns that the .NET SDK selected to build your project has one or more known vulnerabilities. Install a patched SDK, then update global.json if your repository uses it so the build selects that patched version. Microsoft documents this as an opt-in warning; it does not label NETSDK1238 itself “critical.”

What does NETSDK1238 mean?

Microsoft defines NETSDK1238 as an indication that the .NET SDK used to build a project has one or more known Common Vulnerabilities and Exposures (CVEs). The warning includes the SDK version in use, the CVE identifiers, and a suggested version to install. Read those details in your own build output: the diagnostic does not establish that every project has the same affected version or CVEs.

The check is available in .NET 11 Preview 5 and later and is opt-in. Enable it with the MSBuild property CheckSdkVulnerabilities set to true, or pass /p:CheckSdkVulnerabilities=true to a .NET CLI command. See Microsoft’s NETSDK1238 documentation for the diagnostic details.

Why might a build show the warning—or not show it?

By default, the .NET CLI refreshes a local cache of SDK release metadata in the background at most once every 24 hours. During a build, the check reads that cache and does not make network calls. Microsoft says a machine that has never had network access will not emit the warning, so the absence of NETSDK1238 on such a machine is not evidence that its SDK is vulnerability-free.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to fix NETSDK1238

  1. Read the full diagnostic. Note the SDK version, listed CVEs, and suggested fixed version.
  2. Install a patched SDK. Choose a current patched release from the official .NET download page, using a Microsoft distribution route that fits your environment.
  3. Check SDK selection. If the repository contains global.json, update its SDK version as needed to select the patched SDK. Without this change, the project may continue using the vulnerable version even after another SDK is installed.
  4. Build again. Confirm that the project selects the patched SDK and that the warning no longer identifies the vulnerable SDK.

The suggested version in the warning and the currently available patched release can depend on the SDK metadata and time of the build. Use the version and CVE list in your diagnostic, then check the official download page for current releases rather than assuming a particular version applies to every warning.

Choose an installation method

Microsoft documents several Windows installation routes. Choose based on how the machine is managed and how the SDK needs to be installed:

Method Suitable for
Windows installer Standard system-wide installation
WinGet Command-line package management
PowerShell install script CI or non-admin installs
Manual binaries CI or systems without administrative privileges

Follow Microsoft’s instructions for the selected route in Install .NET on Windows. Select the SDK for the machine’s architecture; Microsoft identifies x64 as the most common choice when you are unsure. Downloaded installers can be checked against the checksum published on the official .NET download page. The SDK includes the corresponding runtime, so a separate runtime installation is not generally needed just to obtain that SDK.

Should you suppress the warning?

Microsoft documents ways to disable the diagnostic, including NoWarn, setting CheckSdkVulnerabilities to false, and the DOTNET_SDK_VULNERABILITY_CHECK_DISABLE environment variable. These options silence the warning; they do not patch the SDK or resolve the listed vulnerabilities. Prefer installing and selecting a patched SDK. Suppression is appropriate only when you intentionally need to disable the check and understand that the build will no longer report it.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is NETSDK1238 a “critical” warning?

Microsoft’s NETSDK1238 documentation describes known CVEs in the SDK, but does not call this warning “critical.” Separately, Microsoft’s Windows installation guidance discusses update classifications used with WSUS: .NET updates can be classed as security or critical, and a critical classification can apply to a non-security update. That servicing classification is not a severity label for NETSDK1238. Use the CVEs actually listed in your warning to understand what it reports.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.