VYPR
High severity7.5NVD Advisory· Published Jul 14, 2026· Updated Jul 24, 2026

CVE-2026-47302

CVE-2026-47302

Description

Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
System.Security.Cryptography.XmlNuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.linux-armNuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.linux-arm64NuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.linux-musl-armNuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.linux-musl-arm64NuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.linux-musl-x64NuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.linux-x64NuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.osx-arm64NuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.osx-x64NuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.win-armNuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.win-arm64NuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.win-x64NuGet
>= 10.0.0, < 10.0.1010.0.10
Microsoft.NetCore.App.Runtime.win-x86NuGet
>= 10.0.0, < 10.0.1010.0.10
System.Security.Cryptography.XmlNuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.linux-armNuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.linux-arm64NuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.linux-musl-armNuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.linux-musl-arm64NuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.linux-musl-x64NuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.linux-x64NuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.osx-arm64NuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.osx-x64NuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.win-armNuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.win-arm64NuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.win-x64NuGet
>= 9.0.0, < 9.0.189.0.18
Microsoft.NetCore.App.Runtime.win-x86NuGet
>= 9.0.0, < 9.0.189.0.18
System.Security.Cryptography.XmlNuGet
>= 8.0.0, < 8.0.48.0.4
Microsoft.NetCore.App.Runtime.linux-armNuGet
>= 8.0.0, < 8.0.298.0.29
Microsoft.NetCore.App.Runtime.linux-arm64NuGet
>= 8.0.0, < 8.0.298.0.29
Microsoft.NetCore.App.Runtime.linux-musl-armNuGet
>= 8.0.0, < 8.0.298.0.29
Microsoft.NetCore.App.Runtime.linux-musl-arm64NuGet
>= 8.0.0, < 8.0.298.0.29
Microsoft.NetCore.App.Runtime.linux-musl-x64NuGet
>= 8.0.0, < 8.0.298.0.29
Microsoft.NetCore.App.Runtime.linux-x64NuGet
>= 8.0.0, < 8.0.298.0.29
Microsoft.NetCore.App.Runtime.osx-arm64NuGet
>= 8.0.0, < 8.0.298.0.29
Microsoft.NetCore.App.Runtime.osx-x64NuGet
>= 8.0.0, < 8.0.298.0.29
Microsoft.NetCore.App.Runtime.win-armNuGet
>= 8.0.0, < 8.0.298.0.29
Microsoft.NetCore.App.Runtime.win-arm64NuGet
>= 8.0.0, < 8.0.298.0.29
Microsoft.NetCore.App.Runtime.win-x64NuGet
>= 8.0.0, < 8.0.298.0.29
Microsoft.NetCore.App.Runtime.win-x86NuGet
>= 8.0.0, < 8.0.298.0.29

Affected products

68

Patches

Vulnerability mechanics

References

6

News mentions

3