Description
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Bypass of security controls enabling unauthorized access
Action: Patch
AI Analysis

Impact

The vulnerability originates from inconsistent handling of HTTP requests in Visual Studio Code, producing a request/response smuggling scenario that can be exploited by an attacker to bypass a security feature over a network. This flaw, classified as CWE‑444, allows unauthorized users to evade controls that are otherwise intended to enforce request integrity, potentially granting them unrestricted access to data or execution paths within the application.

Affected Systems

Microsoft’s Visual Studio Code is the affected product. No specific version range is listed, implying that all current releases are potentially impacted until the Microsoft security update is applied.

Risk and Exploitability

The risk is high, with a CVSS score of 8.2, and the EPSS score is not available. Because the flaw can be triggered remotely via crafted HTTP traffic, the attack vector is likely network-based. Although no public exploit has yet been documented, the severity rating and known bypass nature suggest that a determined attacker could leverage the weakness to gain unauthorized access where no proper boundary checks exist.

Generated by OpenCVE AI on September 9, 2026 at 04:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Visual Studio Code update that contains the Microsoft security fix.
  • Configure your network firewall or web application firewall to detect and block request smuggling patterns, such as duplicate or conflicting Content‑Length headers.
  • If an immediate update is not feasible, restrict external access to the affected services and monitor traffic for anomalies indicative of smuggling attacks.

Generated by OpenCVE AI on September 9, 2026 at 04:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:-:*:*

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Title Visual Studio Code Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft visual Studio Code
Weaknesses CWE-444
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft visual Studio Code
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Visual Studio Code
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:50.618Z

Reserved: 2026-08-26T18:40:19.856Z

Link: CVE-2026-81356

cve-icon Vulnrichment

Updated: 2026-09-10T14:30:38.082Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:53.567

Modified: 2026-09-11T21:10:38.950

Link: CVE-2026-81356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T03:00:08Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')