VYPR
High severity7.5NVD Advisory· Published Mar 10, 2026· Updated Apr 2, 2026

CVE-2026-26130

CVE-2026-26130

Description

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.AspNetCore.App.Runtime.linux-armNuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.linux-armNuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.linux-armNuGet
>= 10.0.0, < 10.0.410.0.4
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet
>= 10.0.0, < 10.0.410.0.4
Microsoft.AspNetCore.App.Runtime.linux-musl-armNuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.linux-musl-armNuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.linux-musl-armNuGet
>= 10.0.0, < 10.0.410.0.4
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet
>= 10.0.0, < 10.0.410.0.4
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet
>= 10.0.0, < 10.0.410.0.4
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet
>= 10.0.0, < 10.0.410.0.4
Microsoft.AspNetCore.App.Runtime.osx-arm64NuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.osx-arm64NuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.osx-arm64NuGet
>= 10.0.0, < 10.0.410.0.4
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet
>= 10.0.0, < 10.0.410.0.4
Microsoft.AspNetCore.App.Runtime.win-armNuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.win-armNuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.win-armNuGet
>= 10.0.0, < 10.0.410.0.4
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet
>= 10.0.0, < 10.0.410.0.4
Microsoft.AspNetCore.App.Runtime.win-x64NuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.win-x64NuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.win-x64NuGet
>= 10.0.0, < 10.0.410.0.4
Microsoft.AspNetCore.App.Runtime.win-x86NuGet
>= 8.0.0, < 8.0.258.0.25
Microsoft.AspNetCore.App.Runtime.win-x86NuGet
>= 9.0.0, < 9.0.149.0.14
Microsoft.AspNetCore.App.Runtime.win-x86NuGet
>= 10.0.0, < 10.0.410.0.4

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.