High severity7.5NVD Advisory· Published Jan 12, 2021· Updated Jun 17, 2026
CVE-2021-1723
CVE-2021-1723
Description
ASP.NET Core and Visual Studio Denial of Service Vulnerability
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.AspNetCore.Server.Kestrel.CoreNuGet | < 2.1.25 | 2.1.25 |
Microsoft.AspNetCore.App.Runtime.linux-armNuGet | >= 3.1.0, < 3.1.11 | 3.1.11 |
Microsoft.AspNetCore.App.Runtime.linux-armNuGet | >= 5.0.0, < 5.0.2 | 5.0.2 |
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet | >= 3.1.0, < 3.1.11 | 3.1.11 |
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet | >= 5.0.0, < 5.0.2 | 5.0.2 |
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet | >= 3.1.0, < 3.1.11 | 3.1.11 |
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet | >= 5.0.0, < 5.0.2 | 5.0.2 |
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet | >= 3.1.0, < 3.1.11 | 3.1.11 |
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet | >= 5.0.0, < 5.0.2 | 5.0.2 |
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet | >= 3.1.0, < 3.1.11 | 3.1.11 |
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet | >= 5.0.0, < 5.0.2 | 5.0.2 |
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet | >= 3.1.0, < 3.1.11 | 3.1.11 |
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet | >= 5.0.0, < 5.0.2 | 5.0.2 |
Microsoft.AspNetCore.App.Runtime.win-armNuGet | >= 3.1.0, < 3.1.11 | 3.1.11 |
Microsoft.AspNetCore.App.Runtime.win-armNuGet | >= 5.0.0, < 5.0.2 | 5.0.2 |
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet | >= 3.1.0, < 3.1.11 | 3.1.11 |
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet | >= 5.0.0, < 5.0.2 | 5.0.2 |
Microsoft.AspNetCore.App.Runtime.win-x64NuGet | >= 3.1.0, < 3.1.11 | 3.1.11 |
Microsoft.AspNetCore.App.Runtime.win-x64NuGet | >= 5.0.0, < 5.0.2 | 5.0.2 |
Microsoft.AspNetCore.App.Runtime.win-x86NuGet | >= 3.1.0, < 3.1.11 | 3.1.11 |
Microsoft.AspNetCore.App.Runtime.win-x86NuGet | >= 5.0.0, < 5.0.2 | 5.0.2 |
Microsoft.AspNetCore.App.Runtime.linux-musl-armNuGet | >= 5.0.1, < 5.0.2 | 5.0.2 |
Affected products
19cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*range: >=3.1,<=3.1.10
- cpe:2.3:a:microsoft:asp.net_core:3.1:*:*:*:*:*:*:*range: 3.0
- cpe:2.3:a:microsoft:asp.net_core:5.0:*:*:*:*:*:*:*range: 5.0
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- osv-coords13 versionspkg:bitnami/aspnet-corepkg:nuget/microsoft.aspnetcore.app.runtime.linux-armpkg:nuget/microsoft.aspnetcore.app.runtime.linux-arm64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-musl-armpkg:nuget/microsoft.aspnetcore.app.runtime.linux-musl-arm64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-musl-x64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-x64pkg:nuget/microsoft.aspnetcore.app.runtime.osx-x64pkg:nuget/microsoft.aspnetcore.app.runtime.win-armpkg:nuget/microsoft.aspnetcore.app.runtime.win-arm64pkg:nuget/microsoft.aspnetcore.app.runtime.win-x64pkg:nuget/microsoft.aspnetcore.app.runtime.win-x86pkg:nuget/microsoft.aspnetcore.server.kestrel.core
>= 3.1.0, < 3.1.11+ 12 more
- (no CPE)range: >= 3.1.0, < 3.1.11
- (no CPE)range: >= 3.1.0, < 3.1.11
- (no CPE)range: >= 3.1.0, < 3.1.11
- (no CPE)range: >= 5.0.1, < 5.0.2
- (no CPE)range: >= 3.1.0, < 3.1.11
- (no CPE)range: >= 3.1.0, < 3.1.11
- (no CPE)range: >= 3.1.0, < 3.1.11
- (no CPE)range: >= 3.1.0, < 3.1.11
- (no CPE)range: >= 3.1.0, < 3.1.11
- (no CPE)range: >= 3.1.0, < 3.1.11
- (no CPE)range: >= 3.1.0, < 3.1.11
- (no CPE)range: >= 3.1.0, < 3.1.11
- (no CPE)range: < 2.1.25
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-242j-2gm6-5rwxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-1723ghsaADVISORY
- github.com/dotnet/announcements/issues/170ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/3L27CGRVEWUPELNJOGTCW6GLEDBECB4BghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/RRXHERXW4KR5WCP76UDW5PC7GX3YQLUWghsaWEB
- msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1723nvdWEB
- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1723nvd
News mentions
0No linked articles in our index yet.