Junglewise Threat Intelligence

CVE-2026-26171: Microsoft .NET denial of service via XML entity expansion

CVE-2026-26171 · Severity: high · CVSS 7.5 · Published 2026-04-14

Technologies: Red Hat Enterprise Linux AppStream. Vendors: Red Hat, Microsoft.

Executive brief

A vulnerability in Microsoft .NET could allow a remote attacker to crash applications or make them unresponsive. .NET is a widely used framework for building and running software on Windows and Linux. An exploit could lead to a service outage, preventing customers or employees from accessing critical business applications.

Technical details

A vulnerability exists in .NET 8.0 and 9.0 due to uncontrolled resource consumption, specifically related to improper restriction of recursive entity references in DTDs (XML Entity Expansion). An unauthenticated remote attacker can exploit this by sending specially crafted network requests to a vulnerable .NET application. Successful exploitation can lead to a denial-of-service (DoS) condition by exhausting system resources or triggering a security bypass. Microsoft and Red Hat have released security updates (e.g., .NET SDK 9.0.116 and 8.0.126) to address this issue.

Affected products

  • Microsoft .NET 8.0, 9.0
  • Red Hat Red Hat Enterprise Linux AppStream 8, 9, 10

Timeline

  • 2026-04-14: disclosed
  • 2026-05-04: patched: Red Hat released security advisories and updated packages.

References

Related threats