Denial of Service Vulnerability in ASP.NET Core by Microsoft
CVE-2025-26682

7.5HIGH

Summary

A flaw in ASP.NET Core allows unauthorized attackers to exploit the resource allocation mechanism, potentially leading to a denial of service over a network. This vulnerability enables an attacker to consume system resources without limits, ultimately impacting the availability and performance of the affected services.

Affected Version(s)

ASP.NET Core 8.0 Unknown 1.0.0 < 8.0.15

ASP.NET Core 9.0 Unknown 1.0.0 < 9.0.4

Microsoft Visual Studio 2022 version 17.10 Unknown 17.10 < 17.10.13

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.