ASP.NET Core Denial of Service Vulnerability
Published May 12, 2026
7.5
HIGHCVSS 3.1
EPSS 2.44%
Description
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Affected products
-
Affected
- ≥ 10.0.0, < 10.0.8
- ≥ 8.0.0, < 8.0.27
- ≥ 9.0.0, < 9.0.16
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Microsoft | n/a | unknown | Affected
|
No data.
Red Hat Enterprise Linux 10
dotnet10.0-0:10.0.108-1.el10_2
Fixed · RHSA-2026:22145
Red Hat Enterprise Linux 10
dotnet8.0-0:8.0.127-1.el10_2
Fixed · RHSA-2026:21286
Red Hat Enterprise Linux 10
dotnet9.0-0:9.0.117-1.el10_2
Fixed · RHSA-2026:21754
Red Hat Enterprise Linux 10.0 Extended Update Support
dotnet8.0-0:8.0.127-1.el10_0
Fixed · RHSA-2026:24332
Red Hat Enterprise Linux 10.0 Extended Update Support
dotnet9.0-0:9.0.117-1.el10_0
Fixed · RHSA-2026:24333
Red Hat Enterprise Linux 8
dotnet10.0-0:10.0.108-1.el8_10
Fixed · RHSA-2026:21295
Red Hat Enterprise Linux 8
dotnet8.0-0:8.0.127-1.el8_10
Fixed · RHSA-2026:21291
Red Hat Enterprise Linux 8
dotnet9.0-0:9.0.117-1.el8_10
Fixed · RHSA-2026:21294
Red Hat Enterprise Linux 9
dotnet10.0-0:10.0.108-1.el9_8
Fixed · RHSA-2026:21297
Red Hat Enterprise Linux 9
dotnet8.0-0:8.0.127-1.el9_8
Fixed · RHSA-2026:21293
Red Hat Enterprise Linux 9
dotnet9.0-0:9.0.117-1.el9_8
Fixed · RHSA-2026:21296
Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions
dotnet8.0-0:8.0.127-1.el9_4
Fixed · RHSA-2026:24334
Red Hat Enterprise Linux 9.6 Extended Update Support
dotnet8.0-0:8.0.127-1.el9_6
Fixed · RHSA-2026:24335
Red Hat Enterprise Linux 9.6 Extended Update Support
dotnet9.0-0:9.0.117-1.el9_6
Fixed · RHSA-2026:24336
Red Hat Hardened Images
dotnet10-0-main-10.0.108-1.hum1
Fixed · RHSA-2026:17464
Red Hat Hardened Images
dotnet8-0-main-8.0.127-1.hum1
Fixed · RHSA-2026:17682
Red Hat Hardened Images
dotnet9-0-main-9.0.117-1.hum1
Fixed · RHSA-2026:17527
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | dotnet10.0-0:10.0.108-1.el10_2 | Fixed | RHSA-2026:22145 |
| Red Hat Enterprise Linux 10 | dotnet8.0-0:8.0.127-1.el10_2 | Fixed | RHSA-2026:21286 |
| Red Hat Enterprise Linux 10 | dotnet9.0-0:9.0.117-1.el10_2 | Fixed | RHSA-2026:21754 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | dotnet8.0-0:8.0.127-1.el10_0 | Fixed | RHSA-2026:24332 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | dotnet9.0-0:9.0.117-1.el10_0 | Fixed | RHSA-2026:24333 |
| Red Hat Enterprise Linux 8 | dotnet10.0-0:10.0.108-1.el8_10 | Fixed | RHSA-2026:21295 |
| Red Hat Enterprise Linux 8 | dotnet8.0-0:8.0.127-1.el8_10 | Fixed | RHSA-2026:21291 |
| Red Hat Enterprise Linux 8 | dotnet9.0-0:9.0.117-1.el8_10 | Fixed | RHSA-2026:21294 |
| Red Hat Enterprise Linux 9 | dotnet10.0-0:10.0.108-1.el9_8 | Fixed | RHSA-2026:21297 |
| Red Hat Enterprise Linux 9 | dotnet8.0-0:8.0.127-1.el9_8 | Fixed | RHSA-2026:21293 |
| Red Hat Enterprise Linux 9 | dotnet9.0-0:9.0.117-1.el9_8 | Fixed | RHSA-2026:21296 |
| Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | dotnet8.0-0:8.0.127-1.el9_4 | Fixed | RHSA-2026:24334 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | dotnet8.0-0:8.0.127-1.el9_6 | Fixed | RHSA-2026:24335 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | dotnet9.0-0:9.0.117-1.el9_6 | Fixed | RHSA-2026:24336 |
| Red Hat Hardened Images | dotnet10-0-main-10.0.108-1.hum1 | Fixed | RHSA-2026:17464 |
| Red Hat Hardened Images | dotnet8-0-main-8.0.127-1.hum1 | Fixed | RHSA-2026:17682 |
| Red Hat Hardened Images | dotnet9-0-main-9.0.117-1.hum1 | Fixed | RHSA-2026:17527 |
No package ranges for this CVE.
Remediation
Red Hat statement
As this flaw allows an unauthenticated remote attacker to cause a denial of service, it has been rated with an important severity.
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
References (27)
- https://access.redhat.com/errata/RHSA-2026:17464
- https://access.redhat.com/errata/RHSA-2026:17527
- https://access.redhat.com/errata/RHSA-2026:17682
- https://access.redhat.com/errata/RHSA-2026:21286
- https://access.redhat.com/errata/RHSA-2026:21291
- https://access.redhat.com/errata/RHSA-2026:21293
- https://access.redhat.com/errata/RHSA-2026:21294
- https://access.redhat.com/errata/RHSA-2026:21295
- https://access.redhat.com/errata/RHSA-2026:21296
- https://access.redhat.com/errata/RHSA-2026:21297
- https://access.redhat.com/errata/RHSA-2026:21754
- https://access.redhat.com/errata/RHSA-2026:22145
- https://access.redhat.com/errata/RHSA-2026:24332
- https://access.redhat.com/errata/RHSA-2026:24333
- https://access.redhat.com/errata/RHSA-2026:24334
- https://access.redhat.com/errata/RHSA-2026:24335
- https://access.redhat.com/errata/RHSA-2026:24336
- https://access.redhat.com/security/cve/CVE-2026-42899 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2476605 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-29719 Advisory
- https://github.com/advisories/GHSA-9v76-4qcc-frgh Advisory
- https://github.com/dotnet/announcements/issues/397
- https://github.com/dotnet/aspnetcore/security/advisories/GHSA-9v76-4qcc-frgh
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42899 vendor-advisorypatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-42899
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42899.json
- https://www.cve.org/CVERecord?id=CVE-2026-42899
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub