CVE-2026-69304HighCVSS 5.9

ASP.NET Core Denial of Service Vulnerability

Published
September 11, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

🎯 Affected products9

  • .NET 10.0 installed on Windows
  • .NET 8.0 installed on Windows
  • .NET 9.0 installed on Windows
  • ASP.NET Core 10.0
  • ASP.NET Core 11.0
  • ASP.NET Core 8.0
  • ASP.NET Core 9.0
  • Microsoft Visual Studio 2022 version 17.14
  • Microsoft Visual Studio 2026 version 18.9

✅ Remediation

Security Update — fixed build 11.0 RC1 KB5126106 (Security Update) — fixed build 10.0.12 KB5126105 (Security Update) — fixed build 9.0.20 KB5126104 (Security Update) — fixed build 8.0.31 KBRelease Notes (Security Update) — fixed build 18.9.3 KBRelease Notes (Security Update) — fixed build 17.14.40

🔗 References (15)