Denial of Service Vulnerability in ASP.NET Core by Microsoft
CVE-2026-69304

5.9MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
8 September 2026

What is CVE-2026-69304?

The vulnerability in ASP.NET Core arises from improper handling of highly compressed data, allowing unauthorized attackers to exploit this issue to trigger a denial of service condition on affected systems over a network. This flaw may lead to significant service interruptions, disrupting access for legitimate users and impacting overall system reliability. It is crucial for users and administrators to apply the necessary patches as outlined in the vendor advisory for enhanced protection.

Affected Version(s)

.NET 10.0 10.0.0 < 10.0.12

.NET 8.0 8.0.0 < 8.0.31

.NET 9.0 9.0.0 < 9.0.20

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.