Denial of Service Vulnerability in ASP.NET Core by Microsoft
CVE-2025-26682
7.5HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 8 April 2025
Summary
A flaw in ASP.NET Core allows unauthorized attackers to exploit the resource allocation mechanism, potentially leading to a denial of service over a network. This vulnerability enables an attacker to consume system resources without limits, ultimately impacting the availability and performance of the affected services.
Affected Version(s)
ASP.NET Core 8.0 Unknown 1.0.0 < 8.0.15
ASP.NET Core 9.0 Unknown 1.0.0 < 9.0.4
Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.13
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved