Allocation of Resources Without Limits or Throttling Affecting system.security.cryptography.xml package, versions [8.0.0,8.0.4)[9.0.0,9.0.18)[10.0.0,10.0.10)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.62% (46th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DOTNET-SYSTEMSECURITYCRYPTOGRAPHYXML-17980677
  • published15 Jul 2026
  • disclosed31 Dec 1899
  • credit41ae55e9310ff27fa6f26af4727e5590

Introduced: 31 Dec 1899

CVE-2026-50648  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade System.Security.Cryptography.Xml to version 8.0.4, 9.0.18, 10.0.10 or higher.

Overview

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via XML encryption processing in EncryptedXml. An attacker can cause denial of service by supplying specially crafted encrypted XML that triggers uncontrolled resource consumption during XML decryption or processing, potentially exhausting system resources and rendering the application unavailable.

CVSS Base Scores

version 4.0
version 3.1