CVE-2026-26130

Severity
7.5HIGH
EPSS
0.7%
top 28.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10
Latest updateMar 11

Description

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages19 packages

NVDmicrosoft/asp.net_core8.0.08.0.25+2
CVEListV5microsoft/asp.net_core_8.08.08.0.25
CVEListV5microsoft/asp.net_core_9.09.09.0.14
CVEListV5microsoft/asp.net_core_10.010.010.0.4

🔴Vulnerability Details

5
GHSA
.NET Denial of Service Vulnerability2026-03-11
OSV
.NET Denial of Service Vulnerability2026-03-11
OSV
dotnet8, dotnet9, dotnet10 vulnerabilities2026-03-11
OSV
CVE-2026-26130: Allocation of resources without limits or throttling in ASP2026-03-10
CVEList
ASP.NET Core Denial of Service Vulnerability2026-03-10

📋Vendor Advisories

3
Ubuntu
.NET vulnerabilities2026-03-11
Microsoft
ASP.NET Core Denial of Service Vulnerability2026-03-10
Red Hat
asp.net: ASP.NET Core: Denial of Service via uncontrolled resource allocation2026-03-10

🕵️Threat Intelligence

1
Wiz
CVE-2026-26130 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-26130 (HIGH CVSS 7.5) | Allocation of resources without lim | cvebase.io