Excessive CPU Usage Vulnerability in Microsoft .NET 8.0 and .NET 9.0
CVE-2026-25667
7.5HIGH
What is CVE-2026-25667?
A vulnerability exists in ASP.NET Core Kestrel within Microsoft .NET versions 8.0 prior to 8.0.22 and 9.0 prior to 9.0.11. This flaw enables remote attackers to exploit crafted QUIC packets, potentially leading to excessive CPU consumption due to an incorrect exit condition in the HTTP/3 Encoder/Decoder stream processing. Successful exploitation can hamper the performance of the application, rendering it unresponsive to legitimate requests.
References
EPSS Score
14% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved