Inconsistent interpretation of HTTP requests in Microsoft products - CVE-2026-62899
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass a security feature.
The vulnerability exists due to inconsistent interpretation of http requests in .NET when handling http requests. A remote attacker can send crafted http requests to bypass a security feature.
Successful exploitation requires the target system to be configured in a specific manner and knowledge of that setup.
Affected software
Visual Studio
.NET for Linux
.NET for macOS
How to mitigate CVE-2026-62899
Visual Studio - update to 17.14.38
.NET for Linux - addressed in versions 8.0.30, 9.0.19
.NET for macOS - addressed in versions 8.0.30, 9.0.19