Description
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Published: 2026-07-14
Score: 7.5 High
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Allocation of resources without limits or throttling in the .NET runtime can be an attacker who can send requests over a network, leading to denial of service. The vulnerability falls under resource exhaustion (CWE-770) and allows the attacker to exhaust memory or other system resources, potentially halting the target application or host. The impact is loss of availability for the affected service.

Affected Systems

The affected products include Microsoft .NET 10.0, .NET 9.0, .NET 8.0, the .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, and 4.8.1; and the Visual Studio IDEs Microsoft Visual Studio 2022 versions 17.12 and 17.14 and Microsoft Visual Studio 2026 version 18.7.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, but the EPSS score of approximately 1.03% indicates a low but non‑negligible exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread active exploitation is documented. The attack vector is inferred to be remote over a network, requiring an attacker to send specially crafted input that causes the .NET runtime to allocate unbounded resources, thereby exhausting memory or CPU and rendering the service unavailable.

Generated by OpenCVE AI on July 31, 2026 at 05:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security update from Microsoft for the affected .NET releases.
  • Update Visual Studio 2022 to version 17.14 or newer, and Visual Studio 2026 to update 18.7.
  • Configure operating‑system resource limits, such as Windows Resource Manager or cgroups, to throttle memory or CPU usage for the .NET process.
  • Monitor application and server metrics for abnormal resource consumption and set alerts when thresholds are exceeded.

Generated by OpenCVE AI on July 31, 2026 at 05:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cvvh-rhrc-wg4q Microsoft Security Advisory CVE-2026-47302 – .NET Denial of Service Vulnerability
Ubuntu USN Ubuntu USN USN-8553-1 .NET vulnerabilities
History

Sat, 18 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat hummingbird
CPEs cpe:/a:redhat:hummingbird:1
Vendors & Products Redhat
Redhat hummingbird
References
Metrics threat_severity

None

threat_severity

Important


Tue, 14 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
Title .NET Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-770
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net Visual Studio 2022 Visual Studio 2026
Redhat Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:52:51.150Z

Reserved: 2026-05-18T23:53:33.897Z

Link: CVE-2026-47302

cve-icon Vulnrichment

Updated: 2026-07-14T20:39:48.423Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T18:45:32Z

Links: CVE-2026-47302 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:45:03Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling