
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-50651 is a Denial of Service vulnerability in Microsoft .NET's HTTP client (System.Net.Http) caused by allocation of resources without limits or throttling. An unauthenticated remote attacker can exploit the HTTP/2 protocol to trigger an out-of-memory (OOM) condition in the SocketsHttpHandler Http2Connection component via a SETTINGS/PING ACK flood. Affected versions include .NET 8.0 (< 8.0.29), .NET 9.0 (< 9.0.18), .NET 10.0 (< 10.0.10), Visual Studio 2022 versions 17.12.x (< 17.12.22) and 17.14.x (< 17.14.36), and Visual Studio 2026 version 18.7.x (< 18.7.4). Disclosed on July 14, 2026, it carries a CVSS v3.1 base score of 7.5 (High) (MSRC Advisory, Github Advisory).
The root cause is CWE-770 (Allocation of Resources Without Limits or Throttling) in the SocketsHttpHandler's Http2Connection implementation within System.Net.Http. An attacker can send a flood of HTTP/2 SETTINGS and PING ACK frames to a .NET HTTP client, causing unbounded memory allocation that exhausts available memory and leads to an out-of-memory crash. No authentication or user interaction is required, and the attack is network-accessible with low complexity. The vulnerability was discovered and reported by Miha Zupan of Microsoft (Github Advisory, Red Hat Bugzilla).
Successful exploitation results in an out-of-memory condition that crashes or renders unavailable any .NET service or application using the affected SocketsHttpHandler HTTP/2 client. The impact is limited to availability — there is no confidentiality or integrity impact. Applications deployed as self-contained executables targeting affected .NET versions are also vulnerable and require recompilation and redeployment (Github Advisory, MSRC Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The EPSS score is approximately 0.62–0.84%, placing it in roughly the 54th percentile for exploitation probability within 30 days (Github Advisory). The vulnerability is classified as automatable (no user interaction required), making it straightforward to exploit at scale once a method is developed. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
SocketsHttpHandler with HTTP/2 enabled (e.g., ASP.NET Core services, gRPC endpoints, or any application making outbound HTTP/2 connections).Http2Connection.SocketsHttpHandler Http2Connection causes the process to exhaust available memory, resulting in an out-of-memory exception and service crash or unavailability (Github Advisory, Red Hat Bugzilla).OutOfMemoryException originating from System.Net.Http or SocketsHttpHandler; .NET runtime crash dumps referencing Http2Connection memory exhaustion.dotnet.exe, application host processes) without corresponding increase in legitimate request load; process termination due to OOM errors in application event logs.Microsoft has released patched versions: .NET 8.0.29, .NET 9.0.18, and .NET 10.0.10. For Visual Studio, update to 2022 version 17.12.22 or 17.14.36, or Visual Studio 2026 version 18.7.4. Self-contained applications targeting affected versions must be recompiled and redeployed against the patched runtime. As a temporary workaround until patching is complete, implement network-level rate limiting and resource quotas to restrict HTTP/2 connection rates from untrusted sources. Red Hat has also issued errata (RHSA-2026:41893 through RHSA-2026:41901) for affected RHEL 8, 9, and 10 packages (Github Advisory, Red Hat Bugzilla, MSRC Advisory).
The vulnerability was disclosed as part of Microsoft's July 2026 Patch Tuesday, which addressed a record 570 vulnerabilities including three zero-days, drawing significant community attention (BleepingComputer). Microsoft's .NET team published a servicing update blog post detailing the July 2026 fixes (.NET Blog). The SANS Internet Storm Center also covered the patch release (SANS ISC). Rapid7 included this CVE in their July 2026 Patch Tuesday analysis (Rapid7).
Fix availability across major Linux distributions and their releases.
devel
dotnet10
jammy
dotnet6
noble
dotnet8: 8.0.129-8.0.29-0ubuntu1~24.04.1
resolute
dotnet10: 10.0.110-10.0.10-0ubuntu1~26.04.1
RHEL 8
:appstream:dotnet10.0-0:10.0.110-1.el8_10.src
RHEL 9
:appstream:dotnet8.0-0:8.0.130-1.el9_4.src
RHEL 10
dotnet8.0-0:8.0.130-1.el10_0.src
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."