NUGET · JULY 2026 · EARLY WARNING

Buffer Overflow in EncryptedXml Class:.NET Vulnerability Under Investigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-32203GHSA-6588-8GV4-XFGHSeverity: HIGH

A buffer overflow vulnerability in the EncryptedXml class of System.Security.Cryptography.Xml is under investigation. Microsoft.NET projects using affected package versions may be at risk.

What happened

Reportedly, a buffer overflow vulnerability exists in the EncryptedXml class of System.Security.Cryptography.Xml, which appears to lead to a Denial of Service attack. This vulnerability affects Microsoft.NET projects utilizing the affected package versions. The specific versions under investigation are >=10.0.0,<=10.0.5, >=9.0.0,<=9.0.14, and >=8.0.0,<=8.0.2 for System.Security.Cryptography.Xml (nuget).

To assess your exposure, check if your project is using any of the affected versions of the System.Security.Cryptography.Xml package. If so, it is recommended to upgrade to the patched versions: 10.0.6 for.NET 10, 9.0.15 for.NET 9, and 8.0.3 for.NET 8. Further details and confirmations should be obtained from the primary sources.

For more information, consult the Microsoft Security Advisory CVE-2026-32203 –.NET and Visual Studio Denial of Service Vulnerability (https://github.com/dotnet/runtime/security/advisories/GHSA-6588-8gv4-xfgh). This incident is still under investigation, and the primary sources should be referenced for the most accurate and up-to-date information.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If System.Security.Cryptography.Xml is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats