VYPR
High severity7.5GHSA Advisory· Published Apr 14, 2026· Updated May 6, 2026

CVE-2026-33116

CVE-2026-33116

Description

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
System.Security.Cryptography.XmlNuGet
>= 10.0.0, < 10.0.610.0.6
System.Security.Cryptography.XmlNuGet
>= 9.0.0, < 9.0.159.0.15
System.Security.Cryptography.XmlNuGet
>= 8.0.0, < 8.0.38.0.3

Affected products

9
  • Range: >= 8.0.0, <= 8.0.2
  • cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
    Range: >=10.0.0,<10.0.6
  • cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.7:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.8:*:*:*:*:*:*:*
    • cpe:2.3:a:microsoft:.net_framework:4.8.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

49