CVE-2026-81356: Visual Studio Code Security Feature Bypass Vulnerability
Published Sep 8, 2026
·Updated
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Other sources
Visual Studio Code Security Feature Bypass Vulnerability
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft Visual Studio Code<1.136.2
1.136.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.136.2
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of attacker access is required to exploit this issue?
The vulnerability is remotely exploitable over a network and does not require prior privileges. Successful exploitation does require user interaction.
2
What security impact could exploitation have?
An attacker may bypass a security feature. The provided severity vector indicates high confidentiality impact and low integrity impact, with no stated availability impact.