CyberICT

CVE-2026-45646

Microsoft · Published July 14, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability. Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Affected Products

  • Microsoft.AspNet.OData
  • Microsoft.AspNetCore.OData

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C