ZeroHour

CVE-2026-81356

mass

HTTP Request Smuggling in Microsoft Visual Studio Code Enables Security Feature Bypass

CVSS 3.1
8.2 high
EPSS
<1%p26
Published
()
Modified
AI analysis

CVE-2026-81356 is an HTTP request/response smuggling vulnerability (CWE-444) in Microsoft Visual Studio Code, in which components inconsistently interpret HTTP requests, leading to desynchronized request and response handling. An unauthenticated attacker can exploit it over the network by sending crafted HTTP requests, and the CVSS vector indicates some form of user interaction is required for the attack to complete. Successful exploitation allows the attacker to bypass a security feature, with high impact on confidentiality and low impact on integrity, and no availability impact. All Visual Studio Code users are potentially affected; the provided data does not specify affected version ranges, so consult Microsoft's advisory for details. There are currently no known public proof-of-concepts, no reported in-the-wild exploitation, no CISA KEV listing, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Update Visual Studio Code to the latest stable release and check Microsoft's security advisory for the specific affected and fixed version ranges, since the source data does not list them. For deployments where VS Code relays or proxies HTTP traffic (for example, local development servers or web previews), review traffic for signs of request smuggling; with no known in-the-wild exploitation and an EPSS of 0.3%, patching at the next regular update cycle is reasonable.

Affected
Microsoft Visual Studio Code
Estimated exposure
mass≈ tens of millions of users (VS Code has tens of millions of monthly active users) — Visual Studio Code is one of the most widely used code editors, with publicly reported monthly active user counts in the tens of millions, so the potential installed base far exceeds 1 million users even though the subset actually exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Vendors
microsoft
Products
visual studio code
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.