cbcvebase.
CVE-2025-26682
published 2025-04-08

CVE-2025-26682: Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Affected

18 ranges
VendorProductVersion rangeFixed in
microsoftasp.net_core>= 8.0.0 < 8.0.158.0.15
microsoftasp.net_core>= 9.0.0 < 9.0.49.0.4
microsoftasp.net_core_8.0>= 8.0 < 8.0.158.0.15
microsoftasp.net_core_9.0>= 9.0 < 9.0.49.0.4
microsoftmicrosoft_visual_studio_2022_version_17.10>= 17.10.0 < 17.10.1317.10.13
microsoftmicrosoft_visual_studio_2022_version_17.12>= 17.12.0 < 17.12.717.12.7
microsoftmicrosoft_visual_studio_2022_version_17.13>= 17.13.0 < 17.13.617.13.6
microsoftmicrosoft_visual_studio_2022_version_17.8>= 17.8.0 < 17.8.2017.8.20
microsoftvisual_studio_2022>= 17.10.0 < 17.10.1317.10.13
microsoftvisual_studio_2022>= 17.12.0 < 17.12.717.12.7
microsoftvisual_studio_2022>= 17.13.0 < 17.13.617.13.6
microsoftvisual_studio_2022>= 17.8.0 < 17.8.2017.8.20
msrcasp.net_core_8.0
msrcasp.net_core_9.0
msrcmicrosoft_visual_studio_2022_version_17.10
msrcmicrosoft_visual_studio_2022_version_17.12
msrcmicrosoft_visual_studio_2022_version_17.13
msrcmicrosoft_visual_studio_2022_version_17.8

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH