This release includes the following enhancements: 
Release date: February 5, 2026 Support for .NET 10Support for .NET 10 has been added. See Supported Frameworks. Support for C# 14dotTEST can now analyze code written in C# 14. Support for IDEsThe following IDE is now supported: Updated Static Analysis RulesThe following rules have been updated: Rule ID | Updates |
|---|
CS.EXCEPT.RETHROW | Support for Live Static Analysis has been added. |
Additional Updates- The
.slnx solution file format is now supported.
Resolved Bugs and FRs in 2025.3.1Bug/FR ID | Description |
|---|
CVE-2026-22732 | Critical vulnerability resolved by updating to spring-security version 6.5.9 | CVE-2026-33937 | Critical vulnerability resolved by updating to handlebars version 4.7.9 | DT-24649 | Framework Version of Sample Project | DT-24690 | DotTEST 2025.3 with VS 2026(18.2.1) analyzes all projects instead of selected one |
Resolved Bugs and FRs in 2025.3.2Bug/FR ID | Description |
|---|
DT-24785 | Report cannot be generated via cmd with option -report when folder does not exist |
Resolved Bugs and FRs in 2025.3.4Bug/FR ID | Description |
|---|
CVE-2026-29145 | Critical vulnerability resolved by updating to Tomcat version 10.1.54 |
Resolved Bugs and FRs in 2025.3.5Bug/FR ID | Description |
|---|
GHSA-5m62-pw8w-7w9f, GHSA-h6fc-48rj-7qqh, GHSA-r29c-68gh-xp6x, CVE-2026-41284, GHSA-5mp6-jrq3-r938, GHSA-fv25-8xcx-gqjc, GHSA-gx5v-xp9w-j4cg | Critical vulnerability resolved by upgrading tomcat-embed-core to 10.1.56. | CVE-2026-12143, GHSA-hmw2-7cc7-3qxx | Critical vulnerability resolved by upgrading form-data to 4.0.6. | CVE-2026-54512, CVE-2026-54513, GHSA-j3rv-43j4-c7qm, GHSA-rmj7-2vxq-3g9f | Critical vulnerability resolved by upgrading jackson-databind to 2.21.4. | CVE-2026-40973, CVE-2026-40975 | Critical vulnerability resolved by upgrading spring-boot to 3.5.15. | CVE-2026-41848, CVE-2026-41842, CVE-2026-41850, CVE-2026-41851, CVE-2026-41842, CVE-2026-41838, GHSA-rc42-6c7j-7h5r | Critical vulnerability resolved by upgrading Spring to 6.2.19. | CVE-2026-46681, GHSA-x7j8-49r8-mr43 | Critical vulnerability resolved by upgrading ts-utils to 0.14.0. | CVE-2026-48801, GHSA-22p9-wv53-3rq4 | Critical vulnerability resolved by upgrading linkify-it to 5.0.0. | | DT-24896 | Java SocketClient stopped working and exits with timeout after 1s with getsockopt error code |
|