Junglewise Threat Intelligence

CVE-2026-32203: Microsoft .NET and Visual Studio stack overflow denial of service

CVE-2026-32203 · Severity: high · CVSS 7.5 · Published 2026-04-14

Technologies: Red Hat Enterprise Linux AppStream, Microsoft Visual Studio. Vendors: Red Hat, Microsoft.

Executive brief

A security vulnerability has been identified in a Microsoft .NET component used for processing encrypted XML data. An attacker could exploit this flaw to crash applications that use this library, leading to a denial of service. This could disrupt business operations and service availability for any software relying on these specific .NET versions.

Technical details

A stack-based buffer overflow (CWE-121) exists in the EncryptedXml class within the System.Security.Cryptography.Xml package. The vulnerability is caused by improper input validation (CWE-20) when processing specially crafted XML content. A remote, unauthenticated attacker can exploit this over the network without user interaction to cause a denial of service (DoS) by crashing the application process. The issue affects .NET 8, 9, and 10. Patches are available in versions 8.0.3, 9.0.15, and 10.0.6 respectively.

Affected products

  • Microsoft System.Security.Cryptography.Xml 8.0.0 - 8.0.2, 9.0.0 - 9.0.14, 10.0.0 - 10.0.5

Timeline

  • 2026-04-14: disclosed: Initial advisory publication
  • 2026-04-14: patched: Patched versions released for .NET 8, 9, and 10
  • 2026-07-28: advisory: GitHub Advisory updated

References

Related threats