Junglewise Threat Intelligence

CVE-2026-81356: Visual Studio Code HTTP request/response smuggling

CVE-2026-81356 · Severity: high · CVSS 8.2 · Published 2026-09-08

Executive brief

Visual Studio Code is a widely-used code editor that includes HTTP request testing capabilities. An attacker could exploit inconsistent HTTP request interpretation to bypass security features and gain unauthorized access or execute malicious actions on a developer's machine over a network.

Technical details

The vulnerability is an HTTP request/response smuggling issue in Visual Studio Code, where inconsistent interpretation of HTTP requests allows an attacker to bypass security features. This vulnerability can be exploited over a network without requiring user authentication. The root cause stems from improper handling of ambiguous HTTP request syntax, which allows an attacker to craft malicious requests that are parsed differently by the affected component versus downstream systems. An attacker can leverage this to bypass intended security controls and potentially access sensitive data or functionality.

Affected products

  • Microsoft Visual Studio Code

Timeline

  • 2026-09-08: disclosed

References

Related threats