CVE-2026-42899
published 2026-05-12CVE-2026-42899: Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.43%
83.1th percentile
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 10.0.0 < 10.0.8 | 10.0.8 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 8.0.0 < 8.0.27 | 8.0.27 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 9.0.0 < 9.0.16 | 9.0.16 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 10.0.0 < 10.0.8 | 10.0.8 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
.NET vulnerability
vendor_ubuntu·2026-05-25
CVE-2026-42899 .NET vulnerability
Title: .NET vulnerability
Summary: .NET could be made to consume excessive resources if it received specially
crafted network traffic.
Muhammad Abdul Rehman discovered that .NET incorrectly handled certain
network requests, leading to a loop with an unreachable exit condition. A
remote attacker could possibly use this issue to consume excessive
resources, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dotnet: .NET: infinite loop allows an attacker to cause a denial of service
vendor_redhat·2026-05-12·CVSS 7.5
CVE-2026-42899 [HIGH] CWE-835 dotnet: .NET: infinite loop allows an attacker to cause a denial of service
dotnet: .NET: infinite loop allows an attacker to cause a denial of service
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
A flaw was found in dotnet. An infinite loop in ASP.NET Core allows an unauthenticated remote attacker to cause a denial of service over a network. This issue can lead to an application crash and a high consumption of system resources.
Statement: As this flaw allows an unauthenticated remote attacker to cause a denial of service, it has been rated with an important severity.
Mitigation: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Packa
GHSA
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
ghsa·2026-05-18·CVSS 7.5
CVE-2026-42899 [HIGH] CWE-835 Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-42899 – ASP.NET Core Denial of Service Vulnerability
## Executive Summary:
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 8.0, .NET 9.0, and .NET 10.0. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/397
## CVSS Details
- **Version:** 3.1
- **Severity:**
- **Score:** 7.5
- **Vector:** AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
- **Weakness:** CWE-835: Loop with Unreachable Exit
VulDB
Microsoft ASP.NET up to 5.1 infinite loop
vuldb·2026-05-12
CVE-2026-42899 [LOW] Microsoft ASP.NET up to 5.1 infinite loop
A vulnerability was found in Microsoft ASP.NET up to 5.1 and classified as problematic. This vulnerability affects unknown code. The manipulation results in infinite loop.
This vulnerability is cataloged as CVE-2026-42899. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-60147 openjdk: OpenJDK: Improve certification checking (Oracle CPU 2026-07)
bugzilla·2026-07-21·CVSS 6.5
CVE-2026-60147 [MEDIUM] CVE-2026-60147 openjdk: OpenJDK: Improve certification checking (Oracle CPU 2026-07)
CVE-2026-60147 openjdk: OpenJDK: Improve certification checking (Oracle CPU 2026-07)
OpenJDK can apply two different security meanings to the same wildcard dNSName SAN across certificate policy enforcement and hostname verification. During path validation, DNSName.constrains compares *.foo.com and secret.foo.com literally and returns NAME_SAME_TYPE, so NameConstraintsExtension.verify does not reject the chain when secret.foo.com is an exact-host exclusion. Later, HostnameChecker interprets the same SAN as a wildcard template and accepts secret.foo.com for *.foo.com.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 10
Via RHSA-2026:42899 https://access.redhat.com/errata/RHSA-2026:42899
---
This issue has been add
Bugzilla
CVE-2026-47027 openjdk: OpenJDK: Enhance Jar file processing (Oracle CPU 2026-07)
bugzilla·2026-07-20·CVSS 5.3
CVE-2026-47027 [MEDIUM] CVE-2026-47027 openjdk: OpenJDK: Enhance Jar file processing (Oracle CPU 2026-07)
CVE-2026-47027 openjdk: OpenJDK: Enhance Jar file processing (Oracle CPU 2026-07)
The processImpl() method in SignatureFileVerifier exhibits O(n^2) time complexity when verifying JAR files where different entries have different signer combinations, potentially leading to DoS.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 10
Via RHSA-2026:42899 https://access.redhat.com/errata/RHSA-2026:42899
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux
Bugzilla
CVE-2026-47063 openjdk: OpenJDK: Enhance Jar handling (Oracle CPU 2026-07)
bugzilla·2026-07-20·CVSS 7.5
CVE-2026-47063 [HIGH] CVE-2026-47063 openjdk: OpenJDK: Enhance Jar handling (Oracle CPU 2026-07)
CVE-2026-47063 openjdk: OpenJDK: Enhance Jar handling (Oracle CPU 2026-07)
There exists a potential existential forgery vulnerability in CMS and protocols which use CMS. In Java, CMS is used to sign JAR files.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 10
Via RHSA-2026:42899 https://access.redhat.com/errata/RHSA-2026:42899
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat Enterprise Li
Bugzilla
CVE-2026-47021 openjdk: OpenJDK: Enhance XBM image support (Oracle CPU 2026-07)
bugzilla·2026-07-20·CVSS 5.3
CVE-2026-47021 [MEDIUM] CVE-2026-47021 openjdk: OpenJDK: Enhance XBM image support (Oracle CPU 2026-07)
CVE-2026-47021 openjdk: OpenJDK: Enhance XBM image support (Oracle CPU 2026-07)
The regex defined in XbmImageDecoder (matchRegex) is vulnerable to a DoS attack when the input contains a long string without a closing character; due to excessive backtracking.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 10
Via RHSA-2026:42899 https://access.redhat.com/errata/RHSA-2026:42899
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.6 Extended Updat
Bugzilla
CVE-2026-47059 openjdk: OpenJDK: Enhance AWT ImagingLib (Oracle CPU 2026-07)
bugzilla·2026-07-20·CVSS 3.7
CVE-2026-47059 [LOW] CVE-2026-47059 openjdk: OpenJDK: Enhance AWT ImagingLib (Oracle CPU 2026-07)
CVE-2026-47059 openjdk: OpenJDK: Enhance AWT ImagingLib (Oracle CPU 2026-07)
In Java_sun_awt_image_ImagingLib_convolveBI, when processing images with specific dimensions, the function fails to properly handle boundary conditions which leads to invalid memory access and NULL pointer dereference.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 10
Via RHSA-2026:42899 https://access.redhat.com/errata/RHSA-2026:42899
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red H
Bugzilla
CVE-2026-46968 openjdk: Enhance TLS certificate handling
bugzilla·2026-07-20·CVSS 5.9
CVE-2026-46968 [MEDIUM] CVE-2026-46968 openjdk: Enhance TLS certificate handling
CVE-2026-46968 openjdk: Enhance TLS certificate handling
When a server has wantClientAuth and the client sends a no_certificate
alert, any client certificates are not verified.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 10
Via RHSA-2026:42899 https://access.redhat.com/errata/RHSA-2026:42899
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.8 Update Services for SAP S
Bugzilla
CVE-2026-46917 openjdk: OpenJDK: Improve DTLS handshaking (Oracle CPU 2026-07)
bugzilla·2026-07-20·CVSS 5.3
CVE-2026-46917 [MEDIUM] CVE-2026-46917 openjdk: OpenJDK: Improve DTLS handshaking (Oracle CPU 2026-07)
CVE-2026-46917 openjdk: OpenJDK: Improve DTLS handshaking (Oracle CPU 2026-07)
The DTLS implementation is open to two different DoS attacks.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 10
Via RHSA-2026:42899 https://access.redhat.com/errata/RHSA-2026:42899
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red Hat Enterprise Linux 8.
Bugzilla
CVE-2026-47010 openjdk: OpenJDK: Enhance JPEG handling (Oracle CPU 2026-07)
bugzilla·2026-07-20·CVSS 3.7
CVE-2026-47010 [LOW] CVE-2026-47010 openjdk: OpenJDK: Enhance JPEG handling (Oracle CPU 2026-07)
CVE-2026-47010 openjdk: OpenJDK: Enhance JPEG handling (Oracle CPU 2026-07)
ASAN reports a heap integrity violation.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Red Hat Enterprise Linux 10
Via RHSA-2026:42899 https://access.redhat.com/errata/RHSA-2026:42899
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red Hat Enterprise Linux 8.8 Telecommunications Upd
Bugzilla
CVE-2026-42899 dotnet10.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
bugzilla·2026-05-26·CVSS 7.5
CVE-2026-42899 [HIGH] CVE-2026-42899 dotnet10.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
CVE-2026-42899 dotnet10.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42899 dotnet9.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
bugzilla·2026-05-26·CVSS 7.5
CVE-2026-42899 [HIGH] CVE-2026-42899 dotnet9.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
CVE-2026-42899 dotnet9.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42899 dotnet8.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
bugzilla·2026-05-26·CVSS 7.5
CVE-2026-42899 [HIGH] CVE-2026-42899 dotnet8.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
CVE-2026-42899 dotnet8.0: infinite loop allows an attacker to cause a denial of service [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42899 dotnet: .NET: infinite loop allows an attacker to cause a denial of service
bugzilla·2026-05-12·CVSS 7.5
CVE-2026-42899 [HIGH] CVE-2026-42899 dotnet: .NET: infinite loop allows an attacker to cause a denial of service
CVE-2026-42899 dotnet: .NET: infinite loop allows an attacker to cause a denial of service
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Rapid7
Patch Tuesday - May 2026
blogs_rapid7·2026-05-13·CVSS 10.0
CVE-2026-41089 [CRITICAL] Patch Tuesday - May 2026
Microsoft is publishing 137 vulnerabilities on May 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild or public disclosure for any of these vulnerabilities. So far this month, Microsoft has provided patches to address 133 browser vulnerabilities, which are not included in the Patch Tuesday count above.
## Windows Netlogon: critical RCE
Anyone responsible for securing a domain controller should prioritize remediation of CVE-2026-41089 , which is a critical stack-based buffer overflow in Windows Netlogon with a CVSS v3 base score of 9.8. Exploitation leads to execution in the context of the Netlogon service, so that’s SYSTEM privileges on the domain controller. For most pentesters, that’s the point at which the customer report more or less writes itself. No privileges
Sans Isc
Microsoft May 2026 Patch Tuesday, (Tue, May 12th)
blogs_sans_isc·2026-05-12·CVSS 4.3
CVE-2026-41103 [MEDIUM] Microsoft May 2026 Patch Tuesday, (Tue, May 12th)
Microsoft May 2026 Patch Tuesday
Published: 2026-05-12. Last Updated: 2026-05-12 18:29:36 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
Today's Microsoft patch Tuesday fixes 137 different vulnerabilities. In addition, the update addresses 137 Chromium-related issues affecting Microsoft Edge.
There are no already disclosed or already exploited vulnerabilities included in today's patches. I removed the Chromium issues from the table below and included only the 137 Microsoft issues to make it more readable.
Note that issues related to Microsoft Azure are labeled as "no customer action required.
Significant Vulnerabilities of interest:
CVE-2026-41103: This vulnerability affects the Microsoft SSO Plugin for Jira & Confluence. Exploitation could lead to an elevation of privileges. Wit
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42899https://access.redhat.com/errata/RHSA-2026:17464https://access.redhat.com/errata/RHSA-2026:17527https://access.redhat.com/errata/RHSA-2026:17682https://access.redhat.com/errata/RHSA-2026:21286https://access.redhat.com/errata/RHSA-2026:21291https://access.redhat.com/errata/RHSA-2026:21293https://access.redhat.com/errata/RHSA-2026:21294https://access.redhat.com/errata/RHSA-2026:21295https://access.redhat.com/errata/RHSA-2026:21296https://access.redhat.com/errata/RHSA-2026:21297https://access.redhat.com/errata/RHSA-2026:21754https://access.redhat.com/errata/RHSA-2026:22145https://access.redhat.com/errata/RHSA-2026:24332https://access.redhat.com/errata/RHSA-2026:24333https://access.redhat.com/errata/RHSA-2026:24334https://access.redhat.com/errata/RHSA-2026:24335https://access.redhat.com/errata/RHSA-2026:24336https://access.redhat.com/security/cve/CVE-2026-42899https://bugzilla.redhat.com/show_bug.cgi?id=2476605https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42899.json
2026-05-12
Published