CVE-2026-45591
Vulnerability Summary
Timeline
Description
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 2.43%• Percentile: 82%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
- CWE-770•Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Affected Systems
- microsoft•asp.net core 10.0
≥ 10.0, < 10.0.9
- microsoft•asp.net core 8.0
≥ 8.0, < 8.0.28
- microsoft•asp.net core 9.0
≥ 9.0, < 9.0.17
- microsoft•microsoft visual studio 2026 version 18.6
≥ 18.6.0, < 18.6.3
- microsoft•.net 10.0
≥ 10.0.0, < 10.0.9
- microsoft•.net 8.0
≥ 8.0.0, < 8.0.28
- microsoft•.net 9.0
≥ 9.0.0, < 9.0.17
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-x64
≥ 8.0.0, < 8.0.28 | ≥ 9.0.0, < 9.0.17 | ≥ 10.0.0, < 10.0.9
- NuGet•Microsoft.AspNetCore.App.Runtime.osx-arm64
≥ 8.0.0, < 8.0.28 | ≥ 9.0.0, < 9.0.17 | ≥ 10.0.0, < 10.0.9
- NuGet•Microsoft.AspNetCore.App.Runtime.win-x64
≥ 8.0.0, < 8.0.28 | ≥ 9.0.0, < 9.0.17 | ≥ 10.0.0, < 10.0.9
- NuGet•Microsoft.AspNetCore.SignalR.Protocols.MessagePack
≥ 8.0.0, < 8.0.28 | ≥ 9.0.0, < 9.0.17 | ≥ 10.0.0, < 10.0.9
References (26)
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45591
- https://github.com/dotnet/aspnetcore/security/advisories/GHSA-f8h2-vmm9-qhj6
- https://nvd.nist.gov/vuln/detail/CVE-2026-45591
- https://github.com/dotnet/announcements/issues/405
- https://github.com/dotnet/aspnetcore
- https://github.com/dotnet/aspnetcore/discussions/67100
- https://access.redhat.com/security/cve/CVE-2026-45591
- https://bugzilla.redhat.com/show_bug.cgi?id=2487224
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45591.json
- https://access.redhat.com/errata/RHSA-2026:28007
- https://access.redhat.com/errata/RHSA-2026:28009
- https://access.redhat.com/errata/RHSA-2026:25115
- https://access.redhat.com/errata/RHSA-2026:25111
- https://access.redhat.com/errata/RHSA-2026:25112
- https://access.redhat.com/errata/RHSA-2026:25114
- https://access.redhat.com/errata/RHSA-2026:25110
- https://access.redhat.com/errata/RHSA-2026:25113
- https://access.redhat.com/errata/RHSA-2026:28227
- https://access.redhat.com/errata/RHSA-2026:28011
- https://access.redhat.com/errata/RHSA-2026:28051
- https://access.redhat.com/errata/RHSA-2026:25222
- https://access.redhat.com/errata/RHSA-2026:25220
- https://access.redhat.com/errata/RHSA-2026:25221
- https://access.redhat.com/errata/RHSA-2026:26638
- https://access.redhat.com/errata/RHSA-2026:26994
- https://access.redhat.com/errata/RHSA-2026:17527