High severity7.5NVD Advisory· Published Apr 8, 2025· Updated Jun 17, 2026
CVE-2025-26682
CVE-2025-26682
Description
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Affected products
10cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*range: >=8.0.0,<8.0.15
- (no CPE)
- (no CPE)range: 8.0
- (no CPE)range: 9.0
- cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*Range: >=17.8.0,<17.8.20
- Microsoft/Microsoft Visual Studio 2022 version 17.10v5Range: 17.10.0
- Microsoft/Microsoft Visual Studio 2022 version 17.12v5Range: 17.12.0
- Microsoft/Microsoft Visual Studio 2022 version 17.13v5Range: 17.13.0
- Microsoft/Microsoft Visual Studio 2022 version 17.8v5Range: 17.8.0
Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26682nvdVendor Advisory
News mentions
0No linked articles in our index yet.