CVE-2026-50506
Microsoft · Published July 14, 2026
7.5
CVSS v3.1
HIGHPatch availableGet patch
Description
OData for ASP.NET and ASP.NET Core Denial of Service Vulnerability. Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Affected Products
- Microsoft.AspNetCore.OData
- Microsoft.AspNet.OData
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C