NUGET · JULY 2026 · EARLY WARNING

.NET XML Processing Denial of Service Vulnerability

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-47302GHSA-CVVH-RHRC-WG4QSeverity: HIGH

An unverified denial of service vulnerability in.NET XML processing (System.Security.Cryptography.Xml, System.Xml) is under investigation. Affected components include System.Security.Cryptography.Xml and various Microsoft.NetCore.App.Runtime packages.

What happened

An early warning has been issued regarding a potential denial of service vulnerability in.NET XML processing. The vulnerability, tracked as CVE-2026-47302 and GHSA-CVVH-RHRC-WG4Q, reportedly affects XML encryption handling in XML parsing, potentially leading to excessive resource consumption or application crashes. The affected components are System.Security.Cryptography.Xml (nuget) versions >=10.0.0,<=10.0.9 and several Microsoft.NetCore.App.Runtime packages for Linux ARM architectures within the same version range.

To assess your exposure, check if your systems utilize any of the affected.NET components within the specified version ranges. It is recommended to consult the primary sources for detailed information and to stay updated on the status of this vulnerability. The primary sources include multiple Microsoft Security Advisories on the dotnet/runtime GitHub repository.

While the vulnerability is still under investigation and not yet confirmed, it is advisable to monitor updates from official sources and consider upgrading to patched versions of the affected packages as a precautionary measure.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If System.Security.Cryptography.Xml is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats