CyberICT

CVE-2026-42899

Microsoft · Published May 12, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

ASP.NET Core Denial of Service Vulnerability. Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Affected Products

  • .NET 8.0 installed on Windows
  • .NET 9.0 installed on Linux
  • .NET 8.0 installed on Mac OS
  • .NET 8.0 installed on Linux

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C