CVE-2026-42899
published 2026-05-12CVE-2026-42899: Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.43%
82.4th percentile
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 10.0.0 < 10.0.8 | 10.0.8 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
.NET vulnerability
vendor_ubuntu·2026-05-25
CVE-2026-42899 .NET vulnerability
Title: .NET vulnerability
Summary: .NET could be made to consume excessive resources if it received specially
crafted network traffic.
Muhammad Abdul Rehman discovered that .NET incorrectly handled certain
network requests, leading to a loop with an unreachable exit condition. A
remote attacker could possibly use this issue to consume excessive
resources, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dotnet: .NET: infinite loop allows an attacker to cause a denial of service
vendor_redhat·2026-05-12·CVSS 7.5
CVE-2026-42899 [HIGH] CWE-835 dotnet: .NET: infinite loop allows an attacker to cause a denial of service
dotnet: .NET: infinite loop allows an attacker to cause a denial of service
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
A flaw was found in dotnet. An infinite loop in ASP.NET Core allows an unauthenticated remote attacker to cause a denial of service over a network. This issue can lead to an application crash and a high consumption of system resources.
Statement: As this flaw allows an unauthenticated remote attacker to cause a denial of service, it has been rated with an important severity.
Mitigation: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Packa
GHSA
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
ghsa·2026-05-18·CVSS 7.5
CVE-2026-42899 [HIGH] CWE-835 Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
## Executive Summary:
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/397
## CVSS Details
- **Version:** 3.1
- **Severity:**
- **Score:** 7.5
- **Vector:** AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
- **Weakness:** CWE-835: Loop with Unreachable Exit
VulDB
Microsoft ASP.NET up to 5.1 infinite loop
vuldb·2026-05-12
CVE-2026-42899 [LOW] Microsoft ASP.NET up to 5.1 infinite loop
A vulnerability was found in Microsoft ASP.NET up to 5.1 and classified as problematic. This vulnerability affects unknown code. The manipulation results in infinite loop.
This vulnerability is cataloged as CVE-2026-42899. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42899 dotnet10.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
bugzilla·2026-05-26·CVSS 7.5
CVE-2026-42899 [HIGH] CVE-2026-42899 dotnet10.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
CVE-2026-42899 dotnet10.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42899 dotnet9.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
bugzilla·2026-05-26·CVSS 7.5
CVE-2026-42899 [HIGH] CVE-2026-42899 dotnet9.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
CVE-2026-42899 dotnet9.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42899 dotnet8.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
bugzilla·2026-05-26·CVSS 7.5
CVE-2026-42899 [HIGH] CVE-2026-42899 dotnet8.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
CVE-2026-42899 dotnet8.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42899 dotnet: .NET: infinite loop allows an attacker to cause a denial of service
bugzilla·2026-05-12·CVSS 7.5
CVE-2026-42899 [HIGH] CVE-2026-42899 dotnet: .NET: infinite loop allows an attacker to cause a denial of service
CVE-2026-42899 dotnet: .NET: infinite loop allows an attacker to cause a denial of service
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Rapid7
Patch Tuesday - May 2026
blogs_rapid7·2026-05-13·CVSS 10.0
CVE-2026-41089 [CRITICAL] Patch Tuesday - May 2026
Microsoft is publishing 137 vulnerabilities on May 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild or public disclosure for any of these vulnerabilities. So far this month, Microsoft has provided patches to address 133 browser vulnerabilities, which are not included in the Patch Tuesday count above.
## Windows Netlogon: critical RCE
Anyone responsible for securing a domain controller should prioritize remediation of CVE-2026-41089 , which is a critical stack-based buffer overflow in Windows Netlogon with a CVSS v3 base score of 9.8. Exploitation leads to execution in the context of the Netlogon service, so that’s SYSTEM privileges on the domain controller. For most pentesters, that’s the point at which the customer report more or less writes itself. No privileges
Sans Isc
Microsoft May 2026 Patch Tuesday, (Tue, May 12th)
blogs_sans_isc·2026-05-12·CVSS 4.3
CVE-2026-41103 [MEDIUM] Microsoft May 2026 Patch Tuesday, (Tue, May 12th)
Microsoft May 2026 Patch Tuesday
Published: 2026-05-12. Last Updated: 2026-05-12 18:29:36 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
Today's Microsoft patch Tuesday fixes 137 different vulnerabilities. In addition, the update addresses 137 Chromium-related issues affecting Microsoft Edge.
There are no already disclosed or already exploited vulnerabilities included in today's patches. I removed the Chromium issues from the table below and included only the 137 Microsoft issues to make it more readable.
Note that issues related to Microsoft Azure are labeled as "no customer action required.
Significant Vulnerabilities of interest:
CVE-2026-41103: This vulnerability affects the Microsoft SSO Plugin for Jira & Confluence. Exploitation could lead to an elevation of privileges. Wit
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42899https://access.redhat.com/errata/RHSA-2026:17464https://access.redhat.com/errata/RHSA-2026:17527https://access.redhat.com/errata/RHSA-2026:17682https://access.redhat.com/errata/RHSA-2026:21286https://access.redhat.com/errata/RHSA-2026:21291https://access.redhat.com/errata/RHSA-2026:21293https://access.redhat.com/errata/RHSA-2026:21294https://access.redhat.com/errata/RHSA-2026:21295https://access.redhat.com/errata/RHSA-2026:21296https://access.redhat.com/errata/RHSA-2026:21297https://access.redhat.com/errata/RHSA-2026:21754https://access.redhat.com/errata/RHSA-2026:22145https://access.redhat.com/errata/RHSA-2026:24332https://access.redhat.com/errata/RHSA-2026:24333https://access.redhat.com/errata/RHSA-2026:24334https://access.redhat.com/errata/RHSA-2026:24335https://access.redhat.com/errata/RHSA-2026:24336https://access.redhat.com/security/cve/CVE-2026-42899https://bugzilla.redhat.com/show_bug.cgi?id=2476605https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42899.json
2026-05-12
Published