CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-32WQ-PPWG-3W4M

GHSA-32WQ-PPWG-3W4M: Denial of Service in EnhancedLinq.Async via Microsoft.Bcl.Memory Out-of-Bounds Read

Alon Barad
Alon Barad
Software Engineer

Apr 2, 2026·4 min read·33 visits

Executive Summary (TL;DR)

A flaw in the Base64Url decoder of Microsoft.Bcl.Memory causes an out-of-bounds read when parsing crafted input. Applications using EnhancedLinq.Async are vulnerable to Denial of Service via process crashes.

EnhancedLinq.Async is vulnerable to a Denial of Service (DoS) attack due to an out-of-bounds read flaw inherited from its transitive dependency on Microsoft.Bcl.Memory. This issue, originally tracked as CVE-2026-26127, allows unauthenticated remote attackers to crash applications by supplying malformed Base64Url-encoded payloads.

Vulnerability Overview

GHSA-32WQ-PPWG-3W4M identifies a transitive Denial of Service (DoS) vulnerability impacting the EnhancedLinq.Async package. The vulnerability is not indigenous to the EnhancedLinq.Async codebase. Instead, it stems from its reliance on the Microsoft.Bcl.Memory NuGet package, which contains a critical flaw in its Base64Url decoding implementation (CVE-2026-26127).

The vulnerability is classified as an Out-of-bounds Read (CWE-125). Unauthenticated attackers can exploit this flaw by submitting specially crafted Base64Url strings to application endpoints that process this data. The lack of adequate bounds checking during the decoding phase triggers an out-of-bounds memory access.

In the context of the .NET Core runtime, an out-of-bounds read in managed memory structures typically results in an unhandled runtime exception. Because this exception originates deep within memory allocation or array slicing mechanisms, it often bypasses standard application-level try-catch blocks, causing the entire host process to terminate unexpectedly.

Root Cause Analysis

The root cause of CVE-2026-26127 resides in the .NET and Microsoft.Bcl.Memory implementation of the Base64Url decoder. The decoder is responsible for translating Base64Url-encoded strings into byte arrays. During this translation, the algorithm computes the expected output buffer size and iterates over the input string to perform bitwise extraction and decoding.

The implementation fails to properly validate the length and composition of the input before advancing its read pointers. When the decoder processes a string with an invalid length, trailing padding inconsistencies, or unexpected non-alphabet characters, the internal pointer arithmetic miscalculates the read boundaries. This arithmetic error forces the algorithm to attempt a read operation past the allocated bounds of the input span.

Because the operation involves unsafe context operations or highly optimized span slicing for performance, the runtime engine detects the out-of-bounds access and throws a fatal execution engine exception or an IndexOutOfRangeException. This behavior creates a reliable mechanism for an external attacker to force application instability.

Exploitation Methodology

Exploitation of this vulnerability is straightforward and requires no specialized tools beyond a standard HTTP client. The attacker must first identify an application endpoint or functionality that accepts user-supplied strings which are subsequently passed into EnhancedLinq.Async and evaluated by the Base64Url decoder.

Common attack vectors include authentication endpoints expecting JWTs, OAuth state parameters, webhook receiver payloads, or data ingestion APIs. The attacker crafts a Base64Url string that structurally violates the expected byte alignment, typically by utilizing an invalid length modulo or truncating the required padding parameters.

Upon transmitting this malformed payload over the network, the target application attempts to deserialize or decode the input. The vulnerable decoding loop executes, triggers the out-of-bounds read offset, and faults the process. An attacker can repeatedly issue this request to maintain a continuous Denial of Service state, preventing legitimate users from accessing the service.

Impact Assessment

The CVSS v3.1 vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, resulting in a Base Score of 7.5. The impact is strictly isolated to the Availability metric. There is no evidence that the out-of-bounds read can be pivoted to achieve arbitrary code execution or to leak sensitive memory contents to the attacker.

Despite the lack of confidentiality or integrity impacts, the availability impact is severe. High-performance .NET web APIs utilizing EnhancedLinq.Async are highly susceptible to sudden termination. This abrupt termination drops all active connections, aborts in-flight transactions, and forces the application infrastructure into a continuous restart loop if an orchestration system (like Kubernetes) is managing the pods.

The widespread use of Base64Url encoding in modern web protocols (such as OpenID Connect and generic token passing) amplifies the likelihood of the vulnerable code path being reachable from untrusted network boundaries.

Remediation and Mitigation

The definitive remediation for this vulnerability requires updating the vulnerable Microsoft.Bcl.Memory component. Since EnhancedLinq.Async inherits this vulnerability transitively, developers must explicitly override the dependency version if a pre-patched version of the primary package is not yet deployed.

Developers must update their project files (.csproj) to explicitly include Microsoft.Bcl.Memory version 9.0.14 or later. This forces the NuGet package manager to resolve the dependency graph using the secured version, bypassing the vulnerable version requested by EnhancedLinq.Async.

<ItemGroup>
  <PackageReference Include="Microsoft.Bcl.Memory" Version="9.0.14" />
</ItemGroup>

As a defense-in-depth measure, developers should implement pre-flight validation on all Base64Url inputs. Ensuring that input strings adhere strictly to length constraints and character sets before passing them to core decoding APIs can prevent malformed payloads from ever reaching the vulnerable code path.

Technical Appendix

CVSS Score
7.5/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Systems

EnhancedLinq.AsyncMicrosoft.Bcl.Memory.NET Ecosystem

Affected Versions Detail

Product
Affected Versions
Fixed Version
EnhancedLinq.Async
Alastair Lundy
< 1.0.0-beta.4Dependent on Microsoft.Bcl.Memory override
Microsoft.Bcl.Memory
Microsoft
< 9.0.149.0.14
AttributeDetail
Vulnerability TypeOut-of-bounds Read
CWE IDCWE-125
Attack VectorNetwork
CVSS Score7.5 (High)
Exploit StatusUnauthenticated DoS
ImpactHigh Availability Loss

MITRE ATT&CK Mapping

T1498Network Denial of Service
Impact
T1190Exploit Public-Facing Application
Initial Access
CWE-125
Out-of-bounds Read

The software reads data past the end, or before the beginning, of the intended buffer.

Vulnerability Timeline

CVE-2026-26127 was publicly disclosed as part of Microsoft's Security Advisory.
2026-03-10
GHSA-32WQ-PPWG-3W4M was published identifying inherited risk in EnhancedLinq.Async.
2026-03-01

References & Sources

  • [1]GitHub Advisory (EnhancedLinq.Async)
  • [2]GitHub Repository Advisory
  • [3]Microsoft Security Advisory (CVE-2026-26127)
  • [4]NuGet Package: EnhancedLinq.Async
  • [5]Related .NET Advisory
Related Vulnerabilities
CVE-2026-26127

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•41 minutes ago•CVE-2026-85024
5.9

CVE-2026-85024: Denial of Service via Uncaught Exception in undici WebSocket Client

A high-severity Denial of Service (DoS) vulnerability exists in the undici WebSocket client implementation when processing compressed frames. The vulnerability is caused by a race condition where event listeners, including error handlers, are stripped from the active zlib stream during cleanup before the stream is fully terminated, leading to an unhandled exception.

Alon Barad
Alon Barad
2 views•7 min read
•about 2 hours ago•GHSA-6VJ9-MWQ6-2F5V
5.9

GHSA-6VJ9-MWQ6-2F5V: Cross-Tenant SMTP Credential Disclosure via Shared-State DNS Cache Pollution in Nodemailer

Nodemailer versions 5.0.0 up to 10.0.1 are vulnerable to process-global state contamination inside the DNS caching subsystem. When SMTPS connections are established in a multi-tenant Node.js process targeting a shared gateway, a lower-privilege attacker can seed the global DNS cache with a malicious TLS servername. When a victim subsequently resolves the same gateway host, Nodemailer retrieves the polluted servername, overwrites the victim's connection settings, redirects the TLS session to the attacker's virtual host, and transmits the victim's cleartext SMTP credentials directly to the attacker.

Alon Barad
Alon Barad
7 views•7 min read
•about 3 hours ago•CVE-2026-83557
5.6

CVE-2026-83557: Polymorphic Deserialization Bypass in FasterXML jackson-databind via java.lang.Comparable

An incomplete denylist vulnerability in FasterXML jackson-databind's DefaultBaseTypeLimitingValidator allows unauthenticated remote attackers to bypass polymorphic type limitations. By declaring properties of type java.lang.Comparable, attackers can instantiate arbitrary Comparable subclasses on the classpath, leading to path traversal, local file access, or application-specific state manipulation.

Alon Barad
Alon Barad
6 views•6 min read
•about 4 hours ago•CVE-2026-101914
6.5

CVE-2026-101914: Authorization Bypass via Case-Insensitive Path Matching in @grpc/grpc-js-xds

An authorization bypass vulnerability exists in the @grpc/grpc-js Node.js package (specifically within the xDS plugin wrapper @grpc/grpc-js-xds) due to a logical error in its Role-Based Access Control (RBAC) path matching component. When case-insensitive path matching is enabled, the matching logic performs a prefix comparison using the startsWith method instead of a strict equality comparison. This logic flaw allows unauthenticated or low-privilege clients with access to a shorter path to gain unauthorized access to longer, more privileged method names that share the same prefix.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 9 hours ago•CVE-2026-61834
4.3

CVE-2026-61834: Prototype Pollution and Mutation of Inherited Built-in Method Objects in scim-patch

A vulnerability in the scim-patch library allows authenticated users to pollute the global JavaScript execution environment. By transmitting a SCIM PATCH operation targeting inherited built-in methods, such as toString, valueOf, or hasOwnProperty, attackers bypass blocklist filters and mutate global prototype objects. This flaw occurs due to the library relying on standard prototype lookup and the 'in' operator during path-resolution and assignment, resolving to shared native functions instead of treating them as missing own-properties.

Alon Barad
Alon Barad
7 views•6 min read
•about 10 hours ago•GHSA-456V-XQ2P-R4CJ
7.8

GHSA-456V-XQ2P-R4CJ: OS Command Injection in code-ollama grep_search Tool

An OS command injection vulnerability in the grep_search tool of the code-ollama package allows remote code execution. This vulnerability is triggered when a local client executes the CLI against a malicious or compromised Ollama server. Due to grep_search being classified as a read-only tool, the CLI executes it automatically in Plan mode without human-in-the-loop validation, leading to zero-interaction local system compromise.

Amit Schendel
Amit Schendel
8 views•5 min read