Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33116

Опубликовано: 14 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

A flaw was found in .NET. A remote attacker could exploit this vulnerability by crafting a malicious XML document that triggers an infinite recursion within the XmlDecryptionTransform component. This could lead to a Denial of Service (DoS), making the affected system unresponsive.

Отчет

This is an Important denial of service vulnerability in .NET's XmlDecryptionTransform. An attacker could exploit this flaw by providing specially crafted XML data, leading to an infinite recursion and causing a denial of service in applications processing such data. This affects Red Hat Enterprise Linux versions 8, 9, and 10, as well as Fedora.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=2457741dotnet: .NET: Denial of Service via Infinite Recursion in XmlDecryptionTransform

EPSS

Процентиль: 80%
0.02142
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
nvd
4 месяца назад

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
msrc
4 месяца назад

.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
github
4 месяца назад

Microsoft Security Advisory CVE-2026-33116 – .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость программной платформы Microsoft .NET, Microsoft .NET Framework и редактора исходного кода Visual Studio, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 80%
0.02142
Низкий

7.5 High

CVSS3