CVE-2026-42899
Microsoft · Published May 12, 2026
7.5
CVSS v3.1
HIGHPatch availableGet patch
Description
ASP.NET Core Denial of Service Vulnerability. Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Affected Products
- .NET 8.0 installed on Windows
- .NET 9.0 installed on Linux
- .NET 8.0 installed on Mac OS
- .NET 8.0 installed on Linux
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C