CVE-2026-50525

Aliases:GHSA-8q5v-6pqq-x66hBIT-dotnet-2026-50525BIT-dotnet-sdk-2026-50525CGA-24vj-69gq-6v75CGA-26j2-grrj-gfgcCGA-2f29-h8mp-28w9CGA-2rq9-ggxw-2c3xCGA-3927-h5cg-fh92CGA-4cf5-ch9m-h4r3CGA-4j4h-4qrx-j695CGA-4jqx-fvgg-85gmCGA-4vvf-h3vr-vg7xCGA-4whh-c96j-637cCGA-562w-3jv3-c829CGA-575f-g7v3-cjw2CGA-57fv-3p8p-8hpjCGA-5frm-5q59-cvqrCGA-5h65-298g-8973CGA-68f6-vmq3-6w5jCGA-6rcf-9fjc-c62mCGA-6rrg-vm3w-5p6mCGA-6w3g-mw5v-r96pCGA-74h9-r895-mhjhCGA-7gj2-j2mh-4vvfCGA-7hp9-5c8f-65h6CGA-84mc-2ghm-99m7CGA-8f8r-q73m-rh3wCGA-8mx4-8mc5-7qf7CGA-958p-h3wm-2fvvCGA-9gw7-grxg-q97wCGA-9jvv-fcj6-2mr7CGA-9v4p-pmqx-9p45CGA-c2v7-p6cj-72xfCGA-ch96-3jcw-hxx6CGA-cmm4-mgwf-xp47CGA-cxhr-989f-jc82CGA-f2w2-jqh5-vjx3CGA-f499-8gvw-m675CGA-fch3-wmg8-ch85CGA-fj8g-72mv-2xqvCGA-fv3m-8hmw-x3gpCGA-g62p-26mf-hjv5CGA-g6r7-hj5c-c7m4CGA-gg96-ff63-63jcCGA-gmp5-jg28-w5pwCGA-h758-75w8-5ch4CGA-h7m5-v8c3-m2qjCGA-j7gg-c53f-pv93CGA-jg3v-pr54-whp7CGA-jrjx-cj99-fprrCGA-jv33-rqcc-c6h5CGA-jvxj-xj4j-69w6CGA-m2g7-52mp-2wc4CGA-mvfp-jv7r-p6h7CGA-p9fj-84f7-fhj5CGA-q698-5848-5xg6CGA-q8xw-rfh5-v88vCGA-q9cq-g6xm-h4w3CGA-qqmj-9426-38r9CGA-qrm3-82q2-pw8mCGA-qv3r-mqcr-ch7wCGA-r2mf-778w-cr2pCGA-rcmx-f9v7-5p2mCGA-rfqj-92wg-mw9mCGA-rj67-ghvv-rjp7CGA-rr7c-ffvf-7947CGA-rv5x-gh9h-f38vCGA-v2xj-5vm7-2wfqCGA-v33x-6fgc-ghf7CGA-v4fc-f3vg-hvqfCGA-vj55-h2fx-wrwpCGA-vrqv-8gfp-crqmCGA-vxg4-67vc-whq5CGA-w9f5-vr7w-2m78CGA-wrhv-wrx3-524xCGA-x4cj-88x5-rff2CGA-xm2v-r22r-vgx7CGA-75m2-hr7v-h47h
Advisory lineage Upstream: 0 Downstream: 18
Analyzed
Published: 14 Jul 2026, 19:29
Last modified:17 Sept 2026, 22:32

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.6% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Jul 2026, 19:29
Published
Vulnerability first disclosed
17 Sept 2026, 22:32
Last Modified
Vulnerability information updated

Description

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.60% Percentile: 48%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardaspnet-8-targeting-pack

    < 8.0.131-r0

  • chainguarddotnet-8-sdk

    < 8.0.129-r1

  • chainguarddotnet-bootstrap-8

    < 8.0.129-r0 | < 8.0.130-r0

  • chainguarddotnet-bootstrap-9

    < 9.0.120-r0

  • chainguarddotnet-sdk-10.0.2

    < 10.0.204-r4

  • chainguarddotnet-sdk-10.0.3

    < 10.0.301-r5

  • chainguardpowershell

    < 7.6.4-r1

  • chainguardpromitor

    < 2.16.0-r3

  • wolfiaspnet-8-targeting-pack

    < 8.0.131-r0

  • wolfidotnet-8-sdk

    < 8.0.129-r1

  • wolfidotnet-bootstrap-8

    < 8.0.129-r0 | < 8.0.130-r0

  • wolfidotnet-bootstrap-9

    < 9.0.120-r0

  • wolfidotnet-sdk-10.0.2

    < 10.0.204-r4

  • wolfidotnet-sdk-10.0.3

    < 10.0.301-r5

  • wolfipowershell

    < 7.6.4-r1

  • wolfipromitor

    < 2.16.0-r3

  • microsoftmicrosoft .net framework 3.5

    ≥ 3.5.0, < 2.0.50727.8983 & 3.0.30729.8978 | ≥ 3.5.0, < 2.0.50727.9182 & 3.0.30729.9168

  • microsoftmicrosoft .net framework 3.5 and 4.7.2

    ≥ 4.7.0, < 2.0.50727.9069 & 3.0.30729.9067 & 4.7.4143.0

  • microsoftmicrosoft .net framework 3.5 and 4.8

    ≥ 4.8.0, < 2.0.50727.9069 & 3.0.30729.9067 & 4.8.4803.0

  • microsoftmicrosoft .net framework 3.5 and 4.8.1

    ≥ 4.8.1, < 2.0.50727.9182 & 3.0.30729.9168 & 4.8.9339.0

  • microsoftmicrosoft .net framework 4.6.2/4.7/4.7.1/4.7.2

    ≥ 4.7.0, < 4.7.4143.0

  • microsoftmicrosoft .net framework 4.8

    ≥ 4.8.0, < 4.8.4803.0

  • microsoftmicrosoft .net framework 4.8.1

    ≥ 4.8.0.0, < 4.8.9340.0

  • microsoftmicrosoft visual studio 2022 version 17.12

    ≥ 17.12.0, < 17.12.22

  • microsoftmicrosoft visual studio 2022 version 17.14

    ≥ 17.14.0, < 17.14.36

  • microsoftmicrosoft visual studio 2026 version 18.7

    ≥ 18.0, < 18.7.4

  • microsoft.net

    ≥ 8.0.0, < 8.0.29 | ≥ 9.0.0, < 9.0.18 | ≥ 10.0.0, < 10.0.6

  • microsoft.net 10.0

    ≥ 10.0.0, < 10.0.6 | ≥ 10.0.0, < 10.0.10

  • microsoft.net 8.0

    ≥ 8.0.0, < 8.0.29

  • microsoft.net 9.0

    ≥ 9.0.0, < 9.0.18

  • microsoft.net_framework

    4.8.1 | 4.8 | 4.6.2 | 4.7 | 4.7.1 | 4.7.2 | 3.5

  • microsoftvisual_studio_2022

    ≥ 17.12.0, < 17.12.22 | ≥ 17.14.0, < 17.14.36

  • microsoftvisual_studio_2026

    ≥ 18.7.0, < 18.7.4

  • NuGetSystem.Security.Cryptography.Xml

    ≥ 10.0.0, < 10.0.10 | ≥ 9.0.0, < 9.0.18 | ≥ 8.0.0, < 8.0.4

References (6)