CVE-2026-81356
massHTTP Request Smuggling in Microsoft Visual Studio Code Enables Security Feature Bypass
CVE-2026-81356 is an HTTP request/response smuggling vulnerability (CWE-444) in Microsoft Visual Studio Code, in which components inconsistently interpret HTTP requests, leading to desynchronized request and response handling. An unauthenticated attacker can exploit it over the network by sending crafted HTTP requests, and the CVSS vector indicates some form of user interaction is required for the attack to complete. Successful exploitation allows the attacker to bypass a security feature, with high impact on confidentiality and low impact on integrity, and no availability impact. All Visual Studio Code users are potentially affected; the provided data does not specify affected version ranges, so consult Microsoft's advisory for details. There are currently no known public proof-of-concepts, no reported in-the-wild exploitation, no CISA KEV listing, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Update Visual Studio Code to the latest stable release and check Microsoft's security advisory for the specific affected and fixed version ranges, since the source data does not list them. For deployments where VS Code relays or proxies HTTP traffic (for example, local development servers or web previews), review traffic for signs of request smuggling; with no known in-the-wild exploitation and an EPSS of 0.3%, patching at the next regular update cycle is reasonable.
| Microsoft Visual Studio Code | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- Vendors
- microsoft
- Products
- visual studio code
- Weakness
- CWE-444
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.