CVE-2026-57099: ASP.NET Core Denial of Service Vulnerability
Published Sep 8, 2026
·Updated
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Other sources
ASP.NET Core Denial of Service Vulnerability
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft Microsoft.AspNetCore.OData<7.8.1
7.8.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.8.1
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:19 PM
Data Sourced
via MITRE·05:19 PM
DescriptionSeverity
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An unauthorized attacker can exploit it remotely over a network. No privileges or user interaction are required.
2
What is the likely impact of a successful attack?
The impact is denial of service. The vulnerability involves resource allocation without limits or throttling, which can exhaust resources and make the affected service unavailable.
3
Is confidentiality or integrity affected?
The provided severity vector indicates no confidentiality or integrity impact. The affected security property is availability.