CVE-2026-33116 Details
Description
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
A denial-of-service vulnerability has been identified in .NET, .NET Framework, and Visual Studio. This issue arises from a loop with an unreachable exit condition, creating an infinite loop that can be exploited by an unauthorized attacker to disrupt service over a network. The vulnerability affects multiple versions of the .NET Framework, as well as .NET 8.0 and 10.0, depending on the operating system.
Users can apply the security update for this vulnerability, which is available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles linked in the 'Security Updates' section.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
| CWE-776 | Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') | redhat-SADP |
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft .net | >= 10.0.0, < 10.0.6 >= 8.0.0, < 8.0.26 >= 9.0.0, < 9.0.15 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| microsoft .net framework | 3.5 - 4.7.2 4.6.2 4.7 4.7.1 4.8 4.8.1 |
CPE
Remediation
| |
| microsoft windows server 2012 | r2 |
CPE
Remediation
| |
| microsoft windows 10 1809 | All versions |
CPE
Remediation
| |
| microsoft windows 10 21h2 | All versions |
CPE
Remediation
| |
| microsoft windows 10 22h2 | All versions |
CPE
Remediation
| |
| microsoft windows server 2022 | All versions |
CPE
Remediation
| |
| microsoft windows 11 22h2 | All versions |
CPE
Remediation
| |
| microsoft windows 11 23h2 | All versions |
CPE
Remediation
| |
| microsoft windows 11 24h2 | All versions |
CPE
Remediation
| |
| microsoft windows 11 25h2 | All versions |
CPE
Remediation
| |
| microsoft windows 11 26h1 | All versions |
CPE
Remediation
| |
| microsoft windows server 2022 23h2 | All versions |
CPE
Remediation
| |
| microsoft windows server 2025 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1607 | All versions |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 25, 2026 | CVE Translated | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | Initial Analysis | [email protected] |
| Apr 14, 2026 | New CVE Received | [email protected] |