High severityCISA KEVNVD Advisory· Published Aug 8, 2023· Updated Oct 21, 2025
.NET and Visual Studio Denial of Service Vulnerability
CVE-2023-38180
Description
.NET and Visual Studio Denial of Service Vulnerability
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet | >= 7.0.0, < 7.0.10 | 7.0.10 |
Microsoft.AspNetCore.App.Runtime.win-x64NuGet | >= 7.0.0, < 7.0.10 | 7.0.10 |
Microsoft.AspNetCore.App.Runtime.win-x86NuGet | >= 7.0.0, < 7.0.10 | 7.0.10 |
Microsoft.AspNetCore.Server.Kestrel.Transport.LibuvNuGet | >= 6.0.0, < 6.0.21 | 6.0.21 |
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet | >= 6.0.0, < 6.0.21 | 6.0.21 |
Microsoft.AspNetCore.App.Runtime.win-x64NuGet | >= 6.0.0, < 6.0.21 | 6.0.21 |
Microsoft.AspNetCore.App.Runtime.win-x86NuGet | >= 6.0.0, < 6.0.21 | 6.0.21 |
Microsoft.AspNetCore.Server.Kestrel.Transport.LibuvNuGet | < 2.1.40 | 2.1.40 |
Microsoft.AspNetCore.Server.Kestrel.Transport.SocketsNuGet | < 2.1.40 | 2.1.40 |
Affected products
6- Microsoft/ASP.NET Core 2.1v5Range: 2.0
- Microsoft/Microsoft Visual Studio 2022 version 17.2v5Range: 17.2.0
- Microsoft/Microsoft Visual Studio 2022 version 17.4v5Range: 17.4.0
- Microsoft/Microsoft Visual Studio 2022 version 17.6v5Range: 17.6.0
- Microsoft/.NET 6.0v5Range: 6.0.0
- Microsoft/.NET 7.0v5Range: 7.0.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- github.com/advisories/GHSA-vmch-3w2x-vhgqghsaADVISORY
- msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38180ghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-38180ghsaADVISORY
- github.com/dotnet/runtime/issues/90170ghsaWEB
- github.com/dotnet/runtime/security/advisories/GHSA-vmch-3w2x-vhgqghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CL2L4WE5QRT7WEXANYXSKSU43APC5N2VghsaWEB
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NWVZFKTLNMNKPZ755EMRYIA6GHFOWGKYghsaWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalogghsaWEB
News mentions
0No linked articles in our index yet.