CVE-2026-45591
published 2026-06-09CVE-2026-45591: Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.43%
82.4th percentile
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | >= 10.0.0 < 10.0.9 | 10.0.9 |
| microsoft | asp.net_core | >= 8.0.0 < 8.0.28 | 8.0.28 |
| microsoft | asp.net_core | >= 9.0.0 < 9.0.17 | 9.0.17 |
| microsoft | asp.net_core_10.0 | >= 10.0 < 10.0.9 | 10.0.9 |
| microsoft | asp.net_core_8.0 | >= 8.0 < 8.0.28 | 8.0.28 |
| microsoft | asp.net_core_9.0 | >= 9.0 < 9.0.17 | 9.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 10.0.0 < 10.0.9 | 10.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 8.0.0 < 8.0.28 | 8.0.28 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 9.0.0 < 9.0.17 | 9.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 10.0.0 < 10.0.9 | 10.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 8.0.0 < 8.0.28 | 8.0.28 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-arm64 | >= 9.0.0 < 9.0.17 | 9.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x64 | >= 10.0.0 < 10.0.9 | 10.0.9 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x64 | >= 8.0.0 < 8.0.28 | 8.0.28 |
| microsoft | microsoft.aspnetcore.app.runtime.win-x64 | >= 9.0.0 < 9.0.17 | 9.0.17 |
| microsoft | microsoft_visual_studio_2026_version_18.6 | >= 18.6.0 < 18.6.3 | 18.6.3 |
| microsoft | net | >= 10.0.0 < 10.0.9 | 10.0.9 |
| microsoft | net | >= 8.0.0 < 8.0.28 | 8.0.28 |
| microsoft | net | >= 9.0.0 < 9.0.17 | 9.0.17 |
| microsoft | net_10.0 | >= 10.0.0 < 10.0.9 | 10.0.9 |
| microsoft | net_8.0 | >= 8.0.0 < 8.0.28 | 8.0.28 |
| microsoft | net_9.0 | >= 9.0.0 < 9.0.17 | 9.0.17 |
| microsoft | visual_studio_2026 | >= 18.6.0 < 18.6.3 | 18.6.3 |
| ubuntu | dotnet10 | — | — |
| ubuntu | dotnet8 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
ghsa·2026-06-15·CVSS 7.5
CVE-2026-45591 [HIGH] CWE-400 Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability
## Executive summary
Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core SignalR and Blazor Server. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A denial of service vulnerability exists in the MessagePack hub protocol used by SignalR and Blazor Server where an attacker can send deeply-nested MessagePack arrays to cause a stack overflow, resulting in a denial of service.
## Announcement
Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/405
## Affected Platforms
- **Platforms:** All
- **Architectures:** All
## Affected Packag
VulDB
Microsoft ASP.NET Core up to 5-RC1 resource consumption
vuldb·2026-06-09·CVSS 7.5
CVE-2026-45591 [HIGH] Microsoft ASP.NET Core up to 5-RC1 resource consumption
A vulnerability, which was classified as critical, was found in Microsoft ASP.NET Core up to 5-RC1. Affected by this issue is some unknown functionality. Executing a manipulation can lead to resource consumption.
This vulnerability is registered as CVE-2026-45591. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
Ubuntu
.NET vulnerabilities
vendor_ubuntu·2026-06-11·CVSS 6.2
CVE-2026-45491 [MEDIUM] .NET vulnerabilities
Title: .NET vulnerabilities
Summary: Several security issues were fixed in .NET.
It was discovered that .NET did not properly handle link resolution before
file access. A local attacker could use this issue to perform unauthorized
file tampering and write arbitrary files outside of the intended extraction
directory. (CVE-2026-45491)
It was discovered that .NET did not properly handle deeply-nested
MessagePack arrays. An attacker could use this to cause .NET to consume
excessive resources, resulting in a denial of service. (CVE-2026-45591)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption
vendor_redhat·2026-06-09·CVSS 7.5
CVE-2026-45591 [HIGH] CWE-770 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption
dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
A flaw was found in ASP.NET Core. This vulnerability allows an unauthorized attacker to exploit uncontrolled resource consumption, leading to a Denial of Service (DoS) over a network. This means that an attacker can make the affected system unavailable to legitimate users by consuming its resources.
Package: dotnet10.0 (Red Hat Enterprise Linux 10) - Affected
Package: dotnet10.0 (Red Hat Enterprise Linux 9) - Affected
Package: dotnet8.0 (Red Hat Enterprise Linux 9) - Affected
Package: dotnet9.0 (Red Hat Enterprise Linux 9) - Affected
Package: dotnet10.0 (Red Hat Hardened Images) - Affected
Pac
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-45591 dotnet9.0: ASP.NET Core: Denial of Service via uncontrolled resource consumption [fedora-all]
bugzilla·2026-06-10·CVSS 7.5
CVE-2026-45591 [HIGH] CVE-2026-45591 dotnet9.0: ASP.NET Core: Denial of Service via uncontrolled resource consumption [fedora-all]
CVE-2026-45591 dotnet9.0: ASP.NET Core: Denial of Service via uncontrolled resource consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-45591 dotnet8.0: ASP.NET Core: Denial of Service via uncontrolled resource consumption [fedora-all]
bugzilla·2026-06-10·CVSS 7.5
CVE-2026-45591 [HIGH] CVE-2026-45591 dotnet8.0: ASP.NET Core: Denial of Service via uncontrolled resource consumption [fedora-all]
CVE-2026-45591 dotnet8.0: ASP.NET Core: Denial of Service via uncontrolled resource consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-45591 dotnet10.0: ASP.NET Core: Denial of Service via uncontrolled resource consumption [fedora-all]
bugzilla·2026-06-10·CVSS 7.5
CVE-2026-45591 [HIGH] CVE-2026-45591 dotnet10.0: ASP.NET Core: Denial of Service via uncontrolled resource consumption [fedora-all]
CVE-2026-45591 dotnet10.0: ASP.NET Core: Denial of Service via uncontrolled resource consumption [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-45591 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption
bugzilla·2026-06-09·CVSS 7.5
CVE-2026-45591 [HIGH] CVE-2026-45591 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption
CVE-2026-45591 dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:25111 https://access.redhat.com/errata/RHSA-2026:25111
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:25112 https://access.redhat.com/errata/RHSA-2026:25112
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:25115 https://access.redhat.com/errata/RHSA-2026:25115
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RH
Sans Isc
Microsoft June 2026 Patch Tuesday, (Tue, Jun 9th)
blogs_sans_isc·2026-06-09·CVSS 8.8
CVE-2026-49160 [HIGH] Microsoft June 2026 Patch Tuesday, (Tue, Jun 9th)
Microsoft June 2026 Patch Tuesday
Published: 2026-06-09. Last Updated: 2026-06-09 17:34:29 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
Microsoft today released patches for 204 vulnerabilities. 38 of these vulnerabilities are considered critical, and three have been disclosed before today. Six of the vulnerabilities affect Microsoft cloud solutions and do not require any user action. In addition, Microsoft incorporated 360 different vulnerabilities affecting Chromium into its Edge browser.
This is certainly a busier-than-usual patch Tuesday. In particular, the large number of patched Chromium/Edge vulnerabilities underscores the impact of AI tools on vulnerability discovery.
Some noteworthy vulnerabilities:
CVE-2026-49160: This vulnerability was made public a week ago. As implem
Rapid7
Patch Tuesday - June 2026
blogs_rapid7·2026-06-09·CVSS 7.8
CVE-2026-33825 [HIGH] Patch Tuesday - June 2026
Microsoft is publishing 200 vulnerabilities on June 2026 Patch Tuesday . Microsoft is not aware of exploitation in the wild for any of these vulnerabilities, and is aware of public disclosure for three. This is similar to last month’s Patch Tuesday, however several of last month’s vulnerabilities ended up on CISA KEV in the days following their publication. So far this month, Microsoft has provided patches to address 360 browser vulnerabilities, which is an order of magnitude more than has been typical in any given month over the past few years. As usual, browser vulns are not included in the Patch Tuesday count above. Indeed, the vast, and presumably sustained, uptick in the number of browser vulnerabilities has led to Microsoft no longer enumerating Chromium CVEs in the Security Update G
Bleepingcomputer
Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws
blogs_bleepingcomputer·2026-06-09·CVSS 7.8
CVE-2026-45586 [HIGH] Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws
## Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws
## Lawrence Abrams
65 Elevation of Privilege Vulnerabilities
19 Security Feature Bypass Vulnerabilities
55 Remote Code Execution Vulnerabilities
30 Information Disclosure Vulnerabilities
7 Denial of Service Vulnerabilities
27 Spoofing Vulnerabilities
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today.
Therefore, the number of flaws does not include flaws in Mariner, Azure HorizonDB, Microsoft Copilot, Copilot Chat, M365 Copilot, Microsoft Exchange Online, and Microsoft Graph that were fixed by Microsoft earlier this month.
There were also a massive 360 Microsoft Edge/Chromium flaws that were fixed by Google this month, which were excluded from this Patch
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45591https://access.redhat.com/errata/RHSA-2026:17527https://access.redhat.com/errata/RHSA-2026:25110https://access.redhat.com/errata/RHSA-2026:25111https://access.redhat.com/errata/RHSA-2026:25112https://access.redhat.com/errata/RHSA-2026:25113https://access.redhat.com/errata/RHSA-2026:25114https://access.redhat.com/errata/RHSA-2026:25115https://access.redhat.com/errata/RHSA-2026:25220https://access.redhat.com/errata/RHSA-2026:25221https://access.redhat.com/errata/RHSA-2026:25222https://access.redhat.com/errata/RHSA-2026:26638https://access.redhat.com/errata/RHSA-2026:26994https://access.redhat.com/errata/RHSA-2026:28007https://access.redhat.com/errata/RHSA-2026:28009https://access.redhat.com/errata/RHSA-2026:28011https://access.redhat.com/errata/RHSA-2026:28051https://access.redhat.com/errata/RHSA-2026:28227https://access.redhat.com/security/cve/CVE-2026-45591https://bugzilla.redhat.com/show_bug.cgi?id=2487224https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45591.json
2026-06-09
Published