Denial of Service Vulnerability in ASP.NET Core by Microsoft
CVE-2025-26682
7.5HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 8 April 2025
What is CVE-2025-26682?
A flaw in ASP.NET Core allows unauthorized attackers to exploit the resource allocation mechanism, potentially leading to a denial of service over a network. This vulnerability enables an attacker to consume system resources without limits, ultimately impacting the availability and performance of the affected services.
Affected Version(s)
ASP.NET Core 8.0 8.0 < 8.0.15
ASP.NET Core 9.0 9.0 < 9.0.4
Microsoft Visual Studio 2022 version 17.10 17.10.0 < 17.10.13