High severity7.5NVD Advisory· Published Feb 9, 2022· Updated Jun 17, 2026
CVE-2022-21986
CVE-2022-21986
Description
.NET Denial of Service Vulnerability
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.AspNetCore.App.Runtime.win-x64NuGet | >= 5.0.0, < 5.0.14 | 5.0.14 |
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet | >= 5.0.0, < 5.0.14 | 5.0.14 |
Microsoft.AspNetCore.App.Runtime.win-x86NuGet | >= 5.0.0, < 5.0.14 | 5.0.14 |
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet | >= 5.0.0, < 5.0.14 | 5.0.14 |
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet | >= 5.0.0, < 5.0.14 | 5.0.14 |
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet | >= 5.0.0, < 5.0.14 | 5.0.14 |
Microsoft.AspNetCore.App.Runtime.linux-armNuGet | >= 5.0.0, < 5.0.14 | 5.0.14 |
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet | >= 5.0.0, < 5.0.14 | 5.0.14 |
Microsoft.AspNetCore.App.Runtime.win-armNuGet | >= 5.0.0, < 5.0.14 | 5.0.14 |
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet | >= 5.0.0, < 5.0.14 | 5.0.14 |
Microsoft.AspNetCore.App.Runtime.linux-musl-armNuGet | >= 5.0.0, < 5.0.14 | 5.0.14 |
Microsoft.AspNetCore.App.Runtime.linux-armNuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Microsoft.AspNetCore.App.Runtime.linux-musl-armNuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Microsoft.AspNetCore.App.Runtime.osx-arm64NuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Microsoft.AspNetCore.App.Runtime.win-armNuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Microsoft.AspNetCore.App.Runtime.win-x64NuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Microsoft.AspNetCore.App.Runtime.win-x86NuGet | >= 6.0.0, < 6.0.2 | 6.0.2 |
Affected products
26- Microsoft/Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)v5Range: 15.0.0
- Microsoft/Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)v5Range: 16.11.0
- Microsoft/Microsoft Visual Studio 2022 version 17.0v5Range: 17.0.0
- Microsoft/Visual Studio 2019 for Mac version 8.10v5Range: 8.1.0
- Microsoft/.NET 5.0v5Range: 5.0.0
- Microsoft/.NET 6.0v5Range: 6.0.0
- ghsa-coords14 versionspkg:nuget/microsoft.aspnetcore.app.runtime.win-x64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-x64pkg:nuget/microsoft.aspnetcore.app.runtime.win-x86pkg:nuget/microsoft.aspnetcore.app.runtime.osx-x64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-musl-x64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-arm64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-armpkg:nuget/microsoft.aspnetcore.app.runtime.win-arm64pkg:nuget/microsoft.aspnetcore.app.runtime.win-armpkg:nuget/microsoft.aspnetcore.app.runtime.linux-musl-arm64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-musl-armpkg:nuget/microsoft.aspnetcore.app.runtime.osx-arm64pkg:bitnami/dotnetpkg:bitnami/dotnet-sdk
>= 5.0.0, < 5.0.14+ 13 more
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 6.0.0, < 6.0.2
- (no CPE)range: >= 5.0.0, < 5.0.14
- (no CPE)range: >= 5.0.0, < 5.0.14
cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:macos:*:*+ 2 more
- cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:macos:*:*range: >=8.10,<8.10.18
- cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:*range: >=16.0,<=16.11
- cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*range: >=17.0,<17.0.6
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-x459-p2rx-f8ffghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-21986ghsaADVISORY
- github.com/dotnet/announcements/issues/207ghsaWEB
- github.com/dotnet/aspnetcore/security/advisories/GHSA-x459-p2rx-f8ffghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/4HMQOHV7G5TF6OMBN6DNTDOKQQU7KHMMghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/CCTBSBE3PNIMXG6ALX2CQG4ZEH7W3YATghsaWEB
- msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21986nvdWEB
- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-21986ghsaWEB
News mentions
0No linked articles in our index yet.