CVE-2026-50525
Analyzed Analyzed - Analysis Complete

Allocation of Resources Without Limits in .NET

Vulnerability report for CVE-2026-50525, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-24

Assigner: Microsoft Corporation

Description

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-24
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 13 associated CPEs
Vendor Product Version / Range
microsoft .net_framework 4.8.1
microsoft .net_framework 4.8
microsoft .net_framework 4.6.2
microsoft .net_framework 4.7
microsoft .net_framework 4.7.1
microsoft .net_framework 4.7.2
microsoft .net_framework 3.5
microsoft .net From 8.0.0 (inc) to 8.0.29 (exc)
microsoft .net From 9.0.0 (inc) to 9.0.18 (exc)
microsoft .net From 10.0.0 (inc) to 10.0.6 (exc)
microsoft visual_studio_2022 From 17.12.0 (inc) to 17.12.22 (exc)
microsoft visual_studio_2022 From 17.14.0 (inc) to 17.14.36 (exc)
microsoft visual_studio_2026 From 18.7.0 (inc) to 18.7.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50525 is a vulnerability in .NET where resources are allocated without proper limits or throttling. This means that an unauthorized attacker can send requests or inputs that consume excessive system resources, such as memory or processing power, without any restrictions.

As a result, the system may become overwhelmed, leading to a denial of service (DoS) condition. This prevents legitimate users from accessing the affected service or application over a network.

Impact Analysis

This vulnerability can impact you in several ways:

  • Your .NET-based applications or services may become unresponsive or crash due to excessive resource consumption by an attacker.
  • Legitimate users may be unable to access the affected services, leading to downtime or disruption of business operations.
  • If the affected system is part of a larger infrastructure, the denial of service could cascade, impacting other dependent services or systems.

Since the CVSS base score is 7.5 (High severity), the impact is significant, particularly for availability, though it does not directly affect confidentiality or integrity.

Compliance Impact

This vulnerability may affect compliance with common standards and regulations in the following ways:

  • GDPR: While GDPR primarily focuses on data protection and privacy, a denial of service attack could disrupt access to personal data, potentially violating Article 32 (security of processing) or Article 5 (data availability and resilience).
  • HIPAA: For healthcare organizations, a denial of service could prevent access to electronic protected health information (ePHI), violating the HIPAA Security Rule's requirements for ensuring the availability of ePHI (45 CFR Part 164.308(a)(7)).
  • Other standards like ISO 27001 or NIST frameworks require organizations to ensure the availability of information systems. A successful DoS attack could demonstrate a failure to meet these requirements.

However, the specific impact on compliance depends on how the affected system is used and whether it processes regulated data. The vulnerability itself does not directly violate these regulations but could contribute to non-compliance if not mitigated.

Mitigation Strategies

To mitigate CVE-2026-50525, apply the latest security updates provided by Microsoft for .NET.

Refer to the official Microsoft update guide for specific patching instructions and additional mitigation steps.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50525. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart