Description
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper validation of a specified type of input in the Microsoft .NET Framework creates a denial of service condition that can be triggered by an attacker who sends crafted data over a network. The vulnerability is classified as CWE-1287. No privilege escalation or data compromise is required; the impact is loss of availability for any application running on the affected framework.

Affected Systems

Affected versions include Microsoft .NET 10.0, 9.0, and 8.0, as well as Microsoft Visual Studio 2022 releases 17.12 and 17.14 and Microsoft Visual Studio 2026 release 18.7. All listed products are susceptible to the described input validation flaw, which can disrupt service for applications built against those frameworks.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity risk, while an EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote network connection, where an adversary can transmit malicious input from outside the local environment to trigger the denial of service. No additional exploitation prerequisites are identified in the CVE data.

Generated by OpenCVE AI on July 31, 2026 at 05:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft .NET Framework update that addresses CVE-2026-50524.
  • Install any applicable cumulative updates or service packs for Visual Studio 2022 or Visual Studio 2026 via Microsoft Update or the Visual Studio Installer, which may contain the CVE-2026-50524 fix when available.
  • Restrict inbound network traffic to .NET services to reduce the opportunity for unauthorized input.

Generated by OpenCVE AI on July 31, 2026 at 05:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w7cw-xp7h-6j5j Microsoft Security Advisory CVE-2026-50524 – .NET Denial of Service Vulnerability
Ubuntu USN Ubuntu USN USN-8553-1 .NET vulnerabilities
History

Sat, 18 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat hummingbird
CPEs cpe:/a:redhat:hummingbird:1
Vendors & Products Redhat
Redhat hummingbird
References
Metrics threat_severity

None

threat_severity

Important


Tue, 14 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
Title .NET Framework Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-1287
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net Visual Studio 2022 Visual Studio 2026
Redhat Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:24.918Z

Reserved: 2026-06-04T19:00:41.293Z

Link: CVE-2026-50524

cve-icon Vulnrichment

Updated: 2026-07-14T20:39:47.094Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T19:29:53Z

Links: CVE-2026-50524 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:45:03Z

Weaknesses
  • CWE-1287

    Improper Validation of Specified Type of Input