CVE-2026-26130
published 2026-03-10CVE-2026-26130: Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.82%
85.0th percentile
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | >= 10.0.0 < 10.0.4 | 10.0.4 |
| microsoft | asp.net_core | >= 8.0.0 < 8.0.25 | 8.0.25 |
| microsoft | asp.net_core | >= 9.0.0 < 9.0.14 | 9.0.14 |
| microsoft | asp.net_core_10.0 | >= 10.0 < 10.0.4 | 10.0.4 |
| microsoft | asp.net_core_8.0 | >= 8.0 < 8.0.25 | 8.0.25 |
| microsoft | asp.net_core_9.0 | >= 9.0 < 9.0.14 | 9.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 10.0.0 < 10.0.4 | 10.0.4 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 8.0.0 < 8.0.25 | 8.0.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 9.0.0 < 9.0.14 | 9.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 10.0.0 < 10.0.4 | 10.0.4 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 8.0.0 < 8.0.25 | 8.0.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 9.0.0 < 9.0.14 | 9.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 10.0.0 < 10.0.4 | 10.0.4 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 8.0.0 < 8.0.25 | 8.0.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 9.0.0 < 9.0.14 | 9.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 10.0.0 < 10.0.4 | 10.0.4 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 8.0.0 < 8.0.25 | 8.0.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 9.0.0 < 9.0.14 | 9.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 10.0.0 < 10.0.4 | 10.0.4 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 8.0.0 < 8.0.25 | 8.0.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 9.0.0 < 9.0.14 | 9.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 10.0.0 < 10.0.4 | 10.0.4 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 8.0.0 < 8.0.25 | 8.0.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 9.0.0 < 9.0.14 | 9.0.14 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 10.0.0 < 10.0.4 | 10.0.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
dotnet8, dotnet9, dotnet10 vulnerabilities
osv·2026-03-11·CVSS 7.5
CVE-2026-26127 [HIGH] dotnet8, dotnet9, dotnet10 vulnerabilities
dotnet8, dotnet9, dotnet10 vulnerabilities
It was discovered that the .NET Microsoft.Bcl.Memory NuGet package did not
properly handle certain malformed Base64Url encoded input. An attacker could
possibly use this issue to cause .NET to crash, resulting in a denial of
service. This issue only affected .NET 9.0 and .NET 10.0. (CVE-2026-26127)
Bartłomiej Dach discovered that .NET's SignalR server component did not
properly manage resource consumption when processing certain messages. An
attacker could possibly use this issue to exhaust internal buffers, resulting
in a denial of service. (CVE-2026-26130)
GHSA
.NET Denial of Service Vulnerability
ghsa·2026-03-11·CVSS 7.5
CVE-2026-26130 [HIGH] CWE-770 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2026-26130 – .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial of service vulnerability exists in ASP.NET Core due to uncontrolled resource consumption. A specially crafted message to a SignalR server can exhaust an internal buffer and cause a Denial of Service.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/385
## CVSS Details
- **Version:** 3.1
- **Score:** 7.5
- **Vector:** `CVSS:3.1/AV:
OSV
.NET Denial of Service Vulnerability
osv·2026-03-11·CVSS 7.5
CVE-2026-26130 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
# Microsoft Security Advisory CVE-2026-26130 – .NET Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial of service vulnerability exists in ASP.NET Core due to uncontrolled resource consumption. A specially crafted message to a SignalR server can exhaust an internal buffer and cause a Denial of Service.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/385
## CVSS Details
- **Version:** 3.1
- **Score:** 7.5
- **Vector:** `CVSS:3.1/AV:
OSV
CVE-2026-26130: Allocation of resources without limits or throttling in ASP
osv·2026-03-10·CVSS 7.5
CVE-2026-26130 [HIGH] CVE-2026-26130: Allocation of resources without limits or throttling in ASP
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2026-03-11·CVSS 7.5
CVE-2026-26127 [HIGH] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
It was discovered that the .NET Microsoft.Bcl.Memory NuGet package did not
properly handle certain malformed Base64Url encoded input. An attacker could
possibly use this issue to cause .NET to crash, resulting in a denial of
service. This issue only affected .NET 9.0 and .NET 10.0. (CVE-2026-26127)
Bartłomiej Dach discovered that .NET's SignalR server component did not
properly manage resource consumption when processing certain messages. An
attacker could possibly use this issue to exhaust internal buffers, resulting
in a denial of service. (CVE-2026-26130)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
ASP.NET Core Denial of Service Vulnerability
vendor_msrc·2026-03-10·CVSS 7.5
CVE-2026-26130 [HIGH] CWE-770 ASP.NET Core Denial of Service Vulnerability
ASP.NET Core Denial of Service Vulnerability
Description: Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
ASP.NET Core: ASP.NET Core
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://dotnet.microsoft.com/en-us/download/dotnet/8.0
Reference: https://support.microsoft.com/help/5081277
Reference: https://dotnet.microsoft.com/en-us/download/dotnet/9.0
Reference: https://support.microsoft.com/help/5081278
Reference: https://dotnet.microsoft.com/download/dotnet/10.0
Reference: https://support.microsoft.com/help/5081276
Red Hat
asp.net: ASP.NET Core: Denial of Service via uncontrolled resource allocation
vendor_redhat·2026-03-10·CVSS 7.5
CVE-2026-26130 [HIGH] CWE-770 asp.net: ASP.NET Core: Denial of Service via uncontrolled resource allocation
asp.net: ASP.NET Core: Denial of Service via uncontrolled resource allocation
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
A flaw was found in ASP.NET Core. This vulnerability allows an unauthorized attacker to perform a Denial of Service (DoS) attack over a network by allocating resources without limits or throttling. This can lead to the unavailability of the service for legitimate users.
Mitigation: To mitigate this issue, configure resource limits and throttling for ASP.NET Core applications. This can be achieved by implementing request limits within the application configuration or by utilizing resource quotas provided by container orchestration platforms like OpenShift/Kubernetes. Additionally,
No detection rules found.
No public exploits indexed.
Sophos
March Patch Tuesday visits 15 product families
blogs_sophos·2026-03-13
March Patch Tuesday visits 15 product families
Akuter Cyberangriff? Fordern Sie Sofort-Hilfe an
Sophos Central
Partner-Portal
Lizenzen & Accounts
Sophos Home
Sophos Central
Sophos-Central-Anmeldung
Sophos KI
Integrationen
Threat Intelligence
Testversion
Endpoint Protection (Next-Gen Antivirus)
EDR – Endpoint Detection and Response
Server Protection
Mobile Security
XDR – Extended Detection and Response
XDR mit Next-Gen SIEM
ITDR – Identity Threat Detection and Response
Next-Gen Firewall (NGFW)
NDR – Network Detection and Response
Netzwerk-Switches
Wireless Access Points
Workspace Protection
Protected Browser
Zero Trust Network Access (ZTNA)
DNS Protection
Email Monitoring System
E-Mail- und Phishing-Schutz
Awareness-Training für Mitarbeitende
Schutz für Cloud Workloads
Cloud Security Posture Management (CSP
Bleepingcomputer
Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws
blogs_bleepingcomputer·2026-03-10·CVSS 8.8
[HIGH] Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws
## Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws
## Lawrence Abrams
The number of bugs in each vulnerability category is listed below:
46 Elevation of Privilege Vulnerabilities
2 Security Feature Bypass Vulnerabilities
18 Remote Code Execution Vulnerabilities
10 Information Disclosure Vulnerabilities
4 Denial of Service Vulnerabilities
4 Spoofing Vulnerabilities
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today. Therefore, the number of flaws does not include 9 Microsoft Edge flaws, Mariner, Payment Orchestrator Service, Azure, and Microsoft Devices Pricing Program flaws fixed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the
Wiz
CVE-2026-26130 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-26130 [HIGH] CVE-2026-26130 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26130 :
C# vulnerability analysis and mitigation
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Source : NVD
## 7.5
Score
Published March 10, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
C#
ASP.NET Core
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 72
Exploitation Probability (EPSS) 0.7
Affected packages and libraries
dotnet-runtime-9.0-debuginfo
dotnet-sdk-9.0-source-built-artifacts
Sources
AlmaLinux 8 Severity HIGH Has Fix Added at: Mar 13, 2026
AlmaLinux 9 Severity HIGH Has Fix Added at: Mar 13, 2026
Alpine 3.20, 3.21, 3.22, 3.23 Severity HIGH Has Fix Added at: Mar
Sophos
March Patch Tuesday visits 15 product families
blogs_sophos
March Patch Tuesday visits 15 product families
Share This
Microsoft on Tuesday released 84 patches affecting 15 product families – including a few you’ve possibly never encountered. Eight of the addressed issues are considered by Microsoft to be of Critical severity, though none of those affect Windows, nor are they expected to be exploited within the next 30 days. In addition, five of those Critical issues were in fact addressed by Microsoft in advance of Patch Tuesday itself, as we’ll discuss below. Twenty-two have a CVSS base score of 8.0 or higher, including one with a 9.8 base score. None are known to be under active exploit in the wild, but two are publicly disclosed so far.
At patch time, six CVEs are judged more likely to be exploited in the next 30 days by the company’s estimation. Various of this month’s issues are amenable
Wiz
CVE-2026-4111 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-4111 [HIGH] CVE-2026-4111 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4111 :
Rocky Linux vulnerability analysis and mitigation
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.
Source : NVD
## 7.5
Score
Published March 13, 2026
Severity HIGH
CNA Score
Wiz
CVE-2025-14905 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-14905 [MEDIUM] CVE-2025-14905 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14905 :
Rocky Linux vulnerability analysis and mitigation
schema_attr_enum_callback
schema.c
Source : NVD
## 7.2
Score
Published February 23, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 64.4
Exploitation Probability (EPSS) 0.5
Affected packages and libraries
python3-lib389
389-ds-base-legacy-tools
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Mar 29, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 02, 2026
Debian 11, 12, 13 Severity HIGH No Fix Added at: Feb 24, 2026
Echo Severity HIGH No Fix Added at: Feb 24, 2026
Red Hat 6, 7 Severity MEDIUM No Fix Added at: F
Wiz
CVE-2026-1299 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2026-1299 [MEDIUM] CVE-2026-1299 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1299 :
Rocky Linux vulnerability analysis and mitigation
The
email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when
serializing an email message allowing for header injection when an email
is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".
Source : NVD
## 6
Score
Published January 23, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.5
Exploitation Probability (EPSS) N/A
Affected pac
Wiz
CVE-2025-12801 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-12801 [MEDIUM] CVE-2025-12801 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12801 :
Rocky Linux vulnerability analysis and mitigation
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Source : NVD
## 6.5
Score
Published March 4, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probabilit
Wiz
CVE-2025-15366 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2025-15366 [MEDIUM] CVE-2025-15366 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15366 :
Rocky Linux vulnerability analysis and mitigation
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
Source : NVD
## 5.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 23.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python311-testsuite
python36:3.6::python-pymongo
Sources
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Feb 08, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 12, 2026
Chainguard
Wiz
CVE-2026-1761 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-1761 [HIGH] CVE-2026-1761 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1761 :
Rocky Linux vulnerability analysis and mitigation
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.
Source : NVD
## 8.6
Score
Published February 2, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Explo
Wiz
CVE-2026-0719 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-0719 [HIGH] CVE-2026-0719 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0719 :
Rocky Linux vulnerability analysis and mitigation
A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrect memory allocation on the stack, followed by unsafe memory copying. As a result, applications using libsoup may crash unexpectedly, creating a denial-of-service risk.
Source : NVD
## 8.6
Score
Published January 8, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Pe
Wiz
CVE-2026-0865 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-0865 [MEDIUM] CVE-2026-0865 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0865 :
Rocky Linux vulnerability analysis and mitigation
User-controlled header names and values containing newlines can allow injecting HTTP headers.
Source : NVD
## 5.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 32.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python3.15-freethreading-libs
python313-nogil
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Feb 08, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 13, 2026
CBL-Mariner 2.0 Severity MEDIUM Has Fix Added at: Mar 10, 2026
CBL-Mariner 3.0 Severity
Wiz
CVE-2025-15367 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2025-15367 [MEDIUM] CVE-2025-15367 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15367 :
Rocky Linux vulnerability analysis and mitigation
The poplib module, when passed a user-controlled command, can have
additional commands injected using newlines. Mitigation rejects commands
containing control characters.
Source : NVD
## 5.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 23.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python310-tk
python312-tk
Sources
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Feb 08, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 12, 2026
Chainguard Has Fix Added at: Jan 28
Wiz
CVE-2025-14523 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2025-14523 [HIGH] CVE-2025-14523 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14523 :
Rocky Linux vulnerability analysis and mitigation
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
Source : NVD
## 8.2
Score
Published December 11, 2025
Severity HIGH
CNA Score 8.2
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
Bugzilla
CVE-2026-26130 asp.net: ASP.NET Core: Denial of Service via uncontrolled resource allocation
bugzilla·2026-03-10·CVSS 7.5
CVE-2026-26130 [HIGH] CVE-2026-26130 asp.net: ASP.NET Core: Denial of Service via uncontrolled resource allocation
CVE-2026-26130 asp.net: ASP.NET Core: Denial of Service via uncontrolled resource allocation
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:4450 https://access.redhat.com/errata/RHSA-2026:4450
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:4453 https://access.redhat.com/errata/RHSA-2026:4453
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:4451 https://access.redhat.com/errata/RHSA-2026:4451
---
This issue has been addressed in the following products:
Red Hat Enterprise Li
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26130https://access.redhat.com/errata/RHSA-2026:10082https://access.redhat.com/errata/RHSA-2026:10083https://access.redhat.com/errata/RHSA-2026:10084https://access.redhat.com/errata/RHSA-2026:10085https://access.redhat.com/errata/RHSA-2026:10091https://access.redhat.com/errata/RHSA-2026:4443https://access.redhat.com/errata/RHSA-2026:4445https://access.redhat.com/errata/RHSA-2026:4450https://access.redhat.com/errata/RHSA-2026:4451https://access.redhat.com/errata/RHSA-2026:4453https://access.redhat.com/errata/RHSA-2026:4454https://access.redhat.com/errata/RHSA-2026:4455https://access.redhat.com/errata/RHSA-2026:4456https://access.redhat.com/errata/RHSA-2026:4458https://access.redhat.com/security/cve/CVE-2026-26130https://bugzilla.redhat.com/show_bug.cgi?id=2446134https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26130.json
2026-03-10
Published