
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50648 is a Denial of Service vulnerability caused by allocation of resources without limits or throttling in Microsoft .NET Framework and .NET. Disclosed on July 14, 2026, as part of Microsoft's Patch Tuesday, it affects .NET Framework versions 3.5, 4.6.2/4.7/4.7.1/4.7.2, 4.8, and 4.8.1, as well as .NET 8.0 (before 8.0.29), .NET 9.0 (before 9.0.18), .NET 10.0 (before 10.0.6), Visual Studio 2022 (versions 17.12 and 17.14), and Visual Studio 2026 (version 18.7). It carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC).
The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), meaning the affected .NET Framework components fail to impose adequate limits on resource consumption when processing network requests. An unauthenticated remote attacker can send specially crafted network requests that cause the runtime to allocate excessive resources — such as memory or processing time — without bound, ultimately exhausting system resources. No user interaction or privileges are required, and the attack complexity is low, making it straightforward to trigger. Associated attack patterns include excessive allocation (CAPEC-130), exponential data expansion (CAPEC-197), serialized data blowup (CAPEC-229/231), and HTTP/application-layer flooding techniques (Microsoft MSRC).
Successful exploitation results in a Denial of Service condition, rendering affected .NET Framework or .NET-based services unavailable to legitimate users. There is no impact on confidentiality or integrity — the vulnerability is limited to availability. Applications and services hosted on affected .NET runtimes could be crashed or made unresponsive, potentially affecting business-critical workloads that depend on these frameworks (Microsoft MSRC).
Microsoft released patches on July 14, 2026. Organizations should update to the following fixed versions: .NET 8.0.29, .NET 9.0.18, .NET 10.0.6; .NET Framework 3.5 (2.0.50727.8983 / 3.0.30729.8978), 4.6.2–4.7.2 (4.7.4143.0), 4.8 (4.8.4803.0), 4.8.1 (4.8.9339.0); Visual Studio 2022 17.12.22 and 17.14.36; Visual Studio 2026 18.7.4. As interim measures, organizations should implement network-level rate limiting and monitor for abnormal resource consumption patterns on .NET-hosted services (Microsoft MSRC, .NET Dev Blog).
The vulnerability was covered as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities including three zero-days, drawing significant community attention (BleepingComputer). Rapid7 included it in their Patch Tuesday analysis, and SANS ISC published a diary entry covering the July 2026 updates (SANS ISC). The .NET team published official servicing update notes on the Microsoft Dev Blog (.NET Dev Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."