
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50648 is a Denial of Service vulnerability caused by allocation of resources without limits or throttling in Microsoft .NET Framework, .NET, and Visual Studio. It allows an unauthenticated remote attacker to exhaust system resources and deny service over a network. The vulnerability was disclosed and patched on July 14, 2026, as part of Microsoft's July 2026 Patch Tuesday release. Affected products include .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1; .NET 8.0 (before 8.0.29), .NET 9.0 (before 9.0.18), and .NET 10.0 (before 10.0.6); Visual Studio 2022 versions 17.12 and 17.14; and Visual Studio 2026 version 18.7. It carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC, Feedly).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), meaning the affected .NET Framework components fail to impose adequate constraints on resource consumption when processing network requests. An unauthenticated attacker can send specially crafted network requests that trigger unbounded resource allocation — such as memory or CPU — causing the targeted service to become unresponsive or crash. No authentication, user interaction, or elevated privileges are required, and the attack complexity is low, making it straightforward to automate. The vulnerability is associated with attack patterns including HTTP DoS (CAPEC-469), Excessive Allocation (CAPEC-130), and Exponential Data Expansion (CAPEC-197) (Microsoft MSRC, Feedly). A GitHub advisory (GHSA-23rf-6693-g89p) specifically references the System.Security.Cryptography.Xml NuGet package as an affected component (GitHub Advisory).
Successful exploitation results in a high availability impact — affected .NET Framework or .NET services can be crashed or rendered unavailable by an unauthenticated network attacker exhausting system resources without any rate limiting. There is no confidentiality or integrity impact; the vulnerability is purely a Denial of Service condition. Any internet-facing or network-accessible application built on the affected .NET Framework or .NET versions is at risk, potentially disrupting business-critical services and APIs (Microsoft MSRC, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The NVD SSVC assessment marks the vulnerability as automatable with partial technical impact and exploitation status of "none" at time of analysis. The EPSS score is approximately 0.617%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Microsoft MSRC).
Microsoft released patches on July 14, 2026. Organizations should update to the following fixed versions: .NET 8.0.29 or later, .NET 9.0.18 or later, .NET 10.0.6 or later; .NET Framework 4.6.2/4.7/4.7.1/4.7.2 to build 4.7.4143.0 or later, .NET Framework 4.8 to 4.8.4803.0 or later, .NET Framework 4.8.1 to 4.8.9339.0 or later; Visual Studio 2022 to version 17.12.22 or 17.14.36 or later; Visual Studio 2026 to version 18.7.4 or later. Ubuntu users should apply USN-8553-1, and Red Hat/Rocky Linux users should apply RHSA-2026:41901 or equivalent errata. As a network-accessible, unauthenticated DoS vulnerability, patching production systems promptly is the primary recommended action; no configuration-based workaround has been published (Microsoft MSRC, .NET Dev Blog, Ubuntu Advisory).
The vulnerability was covered as part of Microsoft's record-breaking July 2026 Patch Tuesday, which addressed 570 flaws and three zero-days, drawing significant community attention to the overall release rather than this specific CVE (BleepingComputer). Rapid7 included it in their July 2026 Patch Tuesday analysis, and SANS ISC published a diary entry covering the broader release (Rapid7 Blog, SANS ISC). The .NET team published servicing update notes on the Microsoft Dev Blog confirming the fix (.NET Dev Blog).
Fix availability across major Linux distributions and their releases.
RHEL 8
:appstream:dotnet10.0-0:10.0.110-1.el8_10.src
RHEL 9
:appstream:dotnet8.0-0:8.0.130-1.el9_4.src
RHEL 10
dotnet8.0-0:8.0.130-1.el10_0.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."