Apr 2026: .NET Denial of Service Vulnerability
CVE-2026-26171 Published on April 14, 2026

.NET Denial of Service Vulnerability
Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.

Vendor Advisory NVD

Weakness Types

What is a Resource Exhaustion Vulnerability?

The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

CVE-2026-26171 has been classified to as a Resource Exhaustion vulnerability or weakness.

What is a XXE Vulnerability?

The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

CVE-2026-26171 has been classified to as a XXE vulnerability or weakness.


Products Associated with CVE-2026-26171

stack.watch emails you whenever new vulnerabilities are published in Microsoft Net or Canonical Ubuntu Linux. Just hit a watch button to start following.

 
 

Affected Versions

Microsoft .NET 10.0: Microsoft .NET 8.0: Microsoft .NET 9.0: