CVE-2026-56170
Vulnerability Summary
Timeline
Description
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Techniques & Countermeasures
- CWE-770•Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Affected Systems
- microsoft•.net 10.0
≥ 10.0.0, < 10.0.6 | ≥ 10.0.0, < 10.0.10
- microsoft•.net 8.0
≥ 8.0.0, < 8.0.29
- microsoft•.net 9.0
≥ 9.0.0, < 9.0.18
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-arm
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-arm64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-musl-arm
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-musl-x64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.linux-x64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.osx-arm64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.osx-x64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.win-arm
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.win-arm64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.win-x64
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
- NuGet•Microsoft.AspNetCore.App.Runtime.win-x86
≥ 10.0.0, < 10.0.6 | ≥ 9.0.0, < 9.0.15 | ≥ 8.0.0, < 8.0.26
References (6)
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56170
- https://github.com/dotnet/aspnetcore/security/advisories/GHSA-j8gr-8fp3-5q5h
- https://nvd.nist.gov/vuln/detail/CVE-2026-56170
- https://github.com/dotnet/announcements/issues/424
- https://github.com/dotnet/aspnetcore
- https://github.com/dotnet/aspnetcore/discussions/67787