Microsoft Asp.Net Core 8.0 vulnerabilities
7 known vulnerabilities affecting microsoft/asp.net_core_8.0.
Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-26130HIGHCVSS 7.5≥ 8.0, < 8.0.252026-03-10
CVE-2026-26130 [HIGH] CWE-770 CVE-2026-26130: Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2025-55315CRITICALCVSS 9.9PoC≥ 8.0, < 8.0.212025-10-14
CVE-2025-55315 [CRITICAL] CWE-444 CVE-2025-55315: Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core all
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
cvelistv5nvd
CVE-2025-26682HIGHCVSS 7.5≥ 8.0, < 8.0.152025-04-08
CVE-2025-26682 [HIGH] CWE-770 CVE-2025-26682: Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
cvelistv5nvd
CVE-2025-24070HIGHCVSS 7.0≥ 8.0, < 8.0.142025-03-11
CVE-2025-24070 [HIGH] CWE-1390 CVE-2025-24070: Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate p
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
cvelistv5nvd
CVE-2024-21386HIGHCVSS 7.5≥ 8.0, < 8.0.22024-02-13
CVE-2024-21386 [HIGH] CWE-400 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
cvelistv5
CVE-2023-36038HIGHCVSS 8.2≥ 8.0, < 8.0.02023-11-14
CVE-2023-36038 [HIGH] CWE-400 ASP.NET Core Denial of Service Vulnerability
ASP.NET Core Denial of Service Vulnerability
ASP.NET Core Denial of Service Vulnerability
cvelistv5
CVE-2023-36558MEDIUMCVSS 5.5≥ 8.0, < 8.0.02023-11-14
CVE-2023-36558 [MEDIUM] CVE-2023-36558: ASP.NET Core Security Feature Bypass Vulnerability
ASP.NET Core Security Feature Bypass Vulnerability
cvelistv5nvd