CVE-2026-45591

Aliases:GHSA-f8h2-vmm9-qhj6BIT-aspnet-core-2026-45591BIT-dotnet-2026-45591BIT-dotnet-sdk-2026-45591CGA-8xxm-fq83-2mcxCGA-cvx3-6ffv-3hfq
Advisory lineage Upstream: 0 Downstream: 19
Modified
Published: 09 Jun 2026, 17:05
Last modified:25 Aug 2026, 22:43

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
2.48% LOW
2% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jun 2026, 17:05
Published
Vulnerability first disclosed
25 Aug 2026, 22:43
Last Modified
Vulnerability information updated

Description

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 2.48% Percentile: 84%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguarddotnet-bootstrap-8

    < 8.0.129-r0

  • chainguarddotnet-bootstrap-9

    < 9.0.119-r0

  • wolfidotnet-bootstrap-8

    < 8.0.129-r0

  • wolfidotnet-bootstrap-9

    < 9.0.119-r0

  • microsoftasp.net_core

    ≥ 8.0.0, < 8.0.28 | ≥ 9.0.0, < 9.0.17 | ≥ 10.0.0, < 10.0.9

  • microsoftasp.net core 10.0

    ≥ 10.0, < 10.0.9

  • microsoftasp.net core 8.0

    ≥ 8.0, < 8.0.28

  • microsoftasp.net core 9.0

    ≥ 9.0, < 9.0.17

  • microsoftmicrosoft visual studio 2026 version 18.6

    ≥ 18.6.0, < 18.6.3

  • microsoft.net

    ≥ 8.0.0, < 8.0.28 | ≥ 9.0.0, < 9.0.17 | ≥ 10.0.0, < 10.0.9

  • microsoft.net 10.0

    ≥ 10.0.0, < 10.0.9

  • microsoft.net 8.0

    ≥ 8.0.0, < 8.0.28

  • microsoft.net 9.0

    ≥ 9.0.0, < 9.0.17

  • microsoftvisual_studio_2026

    ≥ 18.6.0, < 18.6.3

  • NuGetMicrosoft.AspNetCore.App.Runtime.linux-x64

    ≥ 8.0.0, < 8.0.28 | ≥ 9.0.0, < 9.0.17 | ≥ 10.0.0, < 10.0.9

  • NuGetMicrosoft.AspNetCore.App.Runtime.osx-arm64

    ≥ 8.0.0, < 8.0.28 | ≥ 9.0.0, < 9.0.17 | ≥ 10.0.0, < 10.0.9

  • NuGetMicrosoft.AspNetCore.App.Runtime.win-x64

    ≥ 8.0.0, < 8.0.28 | ≥ 9.0.0, < 9.0.17 | ≥ 10.0.0, < 10.0.9

  • NuGetMicrosoft.AspNetCore.SignalR.Protocols.MessagePack

    ≥ 8.0.0, < 8.0.28 | ≥ 9.0.0, < 9.0.17 | ≥ 10.0.0, < 10.0.9

References (26)