Description
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from the allocation of resources without limits or throttling in .NET Framework, identified as CWE‑770 (Resource Exhaustion). The flaw enables an unauthorized attacker to force the system to consume excessive memory or CPU, thereby disrupting legitimate services over a network. The impact is strictly a denial of service, affecting availability but not confidentiality or integrity.

Affected Systems

Microsoft .NET Framework 3.5, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, 4.8.1, and the newer .NET 8.0, 9.0, and 10.0 releases are all affected. Additionally, Visual Studio 2022 versions 17.12, 17.14, and Visual Studio 2026 18.7 are impacted, as well as the Red Hat Hummingbird 1 component. Any system running these Microsoft or Red Hat products on an untrusted or public network is at risk.

Risk and Exploitability

The description indicates that an unauthorized attacker can deny service over a network. The CVSS score of 7.5 signals a moderate‑to‑high risk level, and the EPSS score of less than 1% suggests that widespread exploitation is unlikely. The vulnerability is not listed in CISA’s KEV catalog. While no direct privilege escalation is disclosed, the resulting denial of service may disrupt business operations and potentially provide a stepping‑stone for further attacks.

Generated by OpenCVE AI on July 31, 2026 at 05:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest security updates for Microsoft .NET Framework (including versions 3.5, 4.6.2/4.7/4.7.1/4.7.2/4.8/4.8.1 and .NET 8/9/10) by installing the patches released on Microsoft’s Update Guide.
  • Upgrade Visual Studio to a version that incorporates the patch; apply the latest updates for Visual Studio 2022 17.12, 17.14 and Visual Studio 2026 18.7.
  • Configure system or network firewalls to restrict inbound traffic to services built on the affected .NET components, limiting exposure to untrusted users.

Generated by OpenCVE AI on July 31, 2026 at 05:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-23rf-6693-g89p Microsoft Security Advisory CVE-2026-50648 – .NET Denial of Service Vulnerability
Ubuntu USN Ubuntu USN USN-8553-1 .NET vulnerabilities
History

Sat, 18 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat hummingbird
CPEs cpe:/a:redhat:hummingbird:1
Vendors & Products Redhat
Redhat hummingbird
References
Metrics threat_severity

None

threat_severity

Important


Tue, 14 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
Title .NET Framework Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-770
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net Visual Studio 2022 Visual Studio 2026
Redhat Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:56:26.436Z

Reserved: 2026-06-05T14:33:50.830Z

Link: CVE-2026-50648

cve-icon Vulnrichment

Updated: 2026-07-14T20:39:43.079Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T19:29:57Z

Links: CVE-2026-50648 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T05:30:07Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling