CVE-2026-56170
Vulnerability Summary
Timeline
Description
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 1.01%• Percentile: 62%
Techniques & Countermeasures
- CWE-770•Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Affected Systems
- ubuntu•dotnet10
< 10.0.106-10.0.6-0ubuntu1~24.04.1 | < 10.0.106-10.0.6-0ubuntu1~25.10.1 | < 10.0.107-10.0.7-0ubuntu1~26.04.1
- ubuntu•dotnet6
all
- ubuntu•dotnet7
all
- ubuntu•dotnet8
< 8.0.126-8.0.26-0ubuntu1~22.04.1 | < 8.0.126-8.0.26-0ubuntu1~24.04.1 | < 8.0.126-8.0.26-0ubuntu1~25.10.1
- ubuntu•dotnet9
< 9.0.115-9.0.14-0ubuntu1~25.10.1
- microsoft•.net
≥ 8.0.0, < 8.0.29 | ≥ 9.0.0, < 9.0.18 | ≥ 10.0.0, < 10.0.6
- microsoft•.net 10.0
≥ 10.0.0, < 10.0.6 | ≥ 10.0.0, < 10.0.10
- microsoft•.net 8.0
≥ 8.0.0, < 8.0.29
- microsoft•.net 9.0
≥ 9.0.0, < 9.0.18
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-arm
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-arm64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-musl-arm
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-musl-x64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-x64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.osx-arm64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.osx-x64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.win-arm
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.win-arm64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.win-x64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.win-x86
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
References (9)
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56170
- https://github.com/dotnet/aspnetcore/security/advisories/GHSA-j8gr-8fp3-5q5h
- https://nvd.nist.gov/vuln/detail/CVE-2026-56170
- https://github.com/dotnet/announcements/issues/424
- https://github.com/dotnet/aspnetcore
- https://github.com/dotnet/aspnetcore/discussions/67787
- https://ubuntu.com/security/CVE-2026-56170
- https://www.cve.org/CVERecord?id=CVE-2026-56170
- https://devblogs.microsoft.com/dotnet/dotnet-and-dotnet-framework-july-2026-servicing-updates