VYPR

Bitnami package

aspnet-core

pkg:bitnami/aspnet-core

Vulnerabilities (23)

  • CVE-2026-69304MedSep 8, 2026
    affected >= 8.0.0, < 8.0.28fixed 8.0.28

    Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2026-45591HigJun 9, 2026
    affected >= 8.0.0, < 8.0.28fixed 8.0.28

    Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2026-40372CriApr 21, 2026
    affected >= 10.0.0, < 10.0.7fixed 10.0.7

    Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-26130HigMar 10, 2026
    affected >= 8.0.0, < 8.0.25fixed 8.0.25

    Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2025-55315CriOct 14, 2025
    affected >= 2.3.0, < 2.3.6fixed 2.3.6

    Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.

  • CVE-2025-7326HigJul 8, 2025
    affected >= 6.0.0, < 7.0.18fixed 7.0.18

    Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry

  • CVE-2025-26682HigApr 8, 2025
    affected >= 8.0.0, < 8.0.15fixed 8.0.15

    Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2025-24070HigMar 11, 2025
    affected >= 8.0.0, < 8.0.14fixed 8.0.14

    Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2024-21404HigFeb 13, 2024
    affected >= 6.0.0, < 6.0.27fixed 6.0.27

    .NET Denial of Service Vulnerability

  • CVE-2024-21386HigFeb 13, 2024
    affected >= 6.0.0, < 6.0.27fixed 6.0.27

    .NET Denial of Service Vulnerability

  • CVE-2023-36558MedNov 14, 2023
    affected >= 6.0.0, < 6.0.25fixed 6.0.25

    ASP.NET Core Security Feature Bypass Vulnerability

  • CVE-2023-36038HigNov 14, 2023
    affected >= 8.0.0, < 8.0.1fixed 8.0.1

    ASP.NET Core Denial of Service Vulnerability

  • CVE-2023-44487HigKEVOct 10, 2023
    affected >= 6.0.0, < 6.0.23fixed 6.0.23

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2023-38180HigKEVAug 8, 2023
    affected >= 2.1.0, < 2.1.40fixed 2.1.40

    .NET and Visual Studio Denial of Service Vulnerability

  • CVE-2023-35391MedAug 8, 2023
    affected >= 2.1.0, < 2.1.40fixed 2.1.40

    ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability

  • CVE-2021-43877HigDec 15, 2021
    affected >= 3.1.0, < 3.1.1fixed 3.1.1

    ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability

  • CVE-2021-34532MedAug 12, 2021
    affected >= 2.1.0, < 2.1.3fixed 2.1.3

    ASP.NET Core and Visual Studio Information Disclosure Vulnerability

  • CVE-2021-1723HigJan 12, 2021
    affected >= 3.1.0, < 3.1.11fixed 3.1.11

    ASP.NET Core and Visual Studio Denial of Service Vulnerability

  • CVE-2020-1045HigSep 11, 2020
    affected >= 3.1.0, < 3.1.8fixed 3.1.8

    A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names. The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.<

  • CVE-2020-1597HigAug 17, 2020
    affected >= 2.1.0, < 2.1.1fixed 2.1.1

    A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without auth

Page 1 of 2