---
id: CVE-2026-33116
title: >-
  Loop with unreachable exit condition ('infinite loop') in .NET, .NET
  Framework, Visual Studio allows an unauthorized attacker to deny service over
  a network.
summary: >-
  Loop with unreachable exit condition ('infinite loop') in .NET, .NET
  Framework, Visual Studio allows an unauthorized attacker to deny service over
  a network.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
  - CWE-400
  - CWE-835
  - CWE-776
vendor: microsoft
product: .net
affected:
  - '.net >= 10.0.0, < 10.0.6'
  - '.net >= 8.0.0, < 8.0.26'
  - '.net >= 9.0.0, < 9.0.15'
  - .net_framework = 3.5
  - .net_framework = 4.7.2
  - .net_framework = 4.6.2
  - .net_framework = 4.7
  - .net_framework = 4.7.1
  - .net_framework = 4.8
  - .net_framework = 4.8.1
patched:
  - .net 9.0.15
published: '2026-04-14'
updated: '2026-07-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33116'
references:
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33116'
    label: secure@microsoft.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:13280'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13281'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13282'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13283'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13693'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8467'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8468'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8469'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8470'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8471'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8472'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8473'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8474'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8475'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:9077'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:9080'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:9205'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-33116'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2457741'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33116.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
  - cve.org
epss: 0.02444
epssPercentile: 0.83632
ingestedAt: '2026-07-26T10:11:59.056Z'
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-04-14T19:48:26.946135Z'
---

## Overview

Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.

## Affected

- `.net >= 10.0.0, < 10.0.6`
- `.net >= 8.0.0, < 8.0.26`
- `.net >= 9.0.0, < 9.0.15`
- `.net_framework = 3.5`
- `.net_framework = 4.7.2`
- `.net_framework = 4.6.2`
- `.net_framework = 4.7`
- `.net_framework = 4.7.1`
- `.net_framework = 4.8`
- `.net_framework = 4.8.1`

## Remediation

Upgrade past the affected range:

- `.net 9.0.15`
