Back

HIGH

ASP.NET Core Denial of Service Vulnerability

Published May 12, 2026

Description

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Affected products

Remediation

Red Hat statement

As this flaw allows an unauthenticated remote attacker to cause a denial of service, it has been rated with an important severity.

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Weaknesses (1)

References (27)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner microsoft
Published May 12, 2026
Updated Aug 10, 2026
Reserved Apr 30, 2026

CISA Vulnrichment

Updated May 12, 2026

NVD

Status Modified
Modified Jul 15, 2026

Red Hat

Severity Important
Public date May 12, 2026
Bugzilla 2476605

ENISA EUVD

Assigner microsoft
Published May 12, 2026
Updated Aug 10, 2026