CyberICT

CVE-2026-26130

Microsoft · Published March 10, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

ASP.NET Core Denial of Service Vulnerability. Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Affected Products

  • ASP.NET Core 8.0
  • ASP.NET Core 9.0
  • ASP.NET Core 10.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C