Severity
7.5HIGH
EPSS
3.2%
top 12.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 16
Latest updateMay 24

Description

A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Patches

🔴Vulnerability Details

5
GHSA
Denial of service in ASP.NET Core2022-05-24
OSV
Denial of service in ASP.NET Core2022-05-24
GHSA
Denial of service in ASP.NET Core2022-05-24
GHSA
Regular Expression Denial of Service in System.Text.RegularExpressions2021-08-04
CVEList
CVE-2019-0980: A denial of service vulnerability exists when2019-05-16

📋Vendor Advisories

4
Red Hat
dotnet: infinite loop in Uri.TryCreate leading to ASP.Net Core Denial of Service2019-05-14
Microsoft
.Net Framework and .Net Core Denial of Service Vulnerability2019-05-14
Red Hat
dotnet: timeouts for regular expressions are not enforced2019-05-14
Red Hat
dotnet: crash in IPAddress.TryCreate leading to ASP.Net Core Denial of Service2019-05-14

💬Community

1
Bugzilla
CVE-2019-0980 dotnet: infinite loop in Uri.TryCreate leading to ASP.Net Core Denial of Service2019-05-02