Executive brief
A security vulnerability has been identified in a Microsoft .NET component used for processing encrypted XML data. An attacker could exploit this flaw to crash applications that use this library, leading to a denial of service. This could disrupt business operations and service availability for any software relying on these specific .NET versions.
Technical details
A stack-based buffer overflow (CWE-121) exists in the EncryptedXml class within the System.Security.Cryptography.Xml package. The vulnerability is caused by improper input validation (CWE-20) when processing specially crafted XML content. A remote, unauthenticated attacker can exploit this over the network without user interaction to cause a denial of service (DoS) by crashing the application process. The issue affects .NET 8, 9, and 10. Patches are available in versions 8.0.3, 9.0.15, and 10.0.6 respectively.
Affected products
- Microsoft System.Security.Cryptography.Xml 8.0.0 - 8.0.2, 9.0.0 - 9.0.14, 10.0.0 - 10.0.5
Timeline
- 2026-04-14: disclosed: Initial advisory publication
- 2026-04-14: patched: Patched versions released for .NET 8, 9, and 10
- 2026-07-28: advisory: GitHub Advisory updated
References
- https://github.com/dotnet/runtime/security/advisories/GHSA-6588-8gv4-xfgh
- https://github.com/dotnet/runtime/issues/126891
- https://github.com/dotnet/announcements/issues/391
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32203.json
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32203