EIP-2026-114819

PRE-CVE

.NET Framework - Tilde Character Denial of Service

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114819. PoCs published by Soroush Dalili.

AI-analyzed exploit summary This is a functional proof-of-concept for a DoS vulnerability in Microsoft .NET Framework caused by sending a large number of HTTP requests with paths containing tilde characters. The exploit leverages the framework's handling of the tilde character to degrade server performance.

Description

.NET Framework - Tilde Character Denial of Service

Exploits (1)

exploitdb WORKING POC VERIFIED
by Soroush Dalili · textdoswindows
https://www.exploit-db.com/exploits/19575

This is a functional proof-of-concept for a DoS vulnerability in Microsoft .NET Framework caused by sending a large number of HTTP requests with paths containing tilde characters. The exploit leverages the framework's handling of the tilde character to degrade server performance.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Microsoft .NET Framework (versions 1.0, 1.1, 2.0, 3.0, 3.5, 4.0)
No auth needed
Prerequisites: A target server running a vulnerable version of .NET Framework · Network access to the target server
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026