Bitnami package
aspnet-core
pkg:bitnami/aspnet-core
Vulnerabilities (23)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-69304 | Med | 5.9 | >= 8.0.0, < 8.0.28 | 8.0.28 | Sep 8, 2026 | Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-45591 | Hig | 7.5 | >= 8.0.0, < 8.0.28 | 8.0.28 | Jun 9, 2026 | Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| CVE-2026-40372 | Cri | 9.1 | >= 10.0.0, < 10.0.7 | 10.0.7 | Apr 21, 2026 | Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2026-26130 | Hig | 7.5 | >= 8.0.0, < 8.0.25 | 8.0.25 | Mar 10, 2026 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| CVE-2025-55315 | Cri | 9.9 | >= 2.3.0, < 2.3.6 | 2.3.6 | Oct 14, 2025 | Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network. | |
| CVE-2025-7326 | Hig | 7.0 | >= 6.0.0, < 7.0.18 | 7.0.18 | Jul 8, 2025 | Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry | |
| CVE-2025-26682 | Hig | 7.5 | >= 8.0.0, < 8.0.15 | 8.0.15 | Apr 8, 2025 | Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | |
| CVE-2025-24070 | Hig | 7.0 | >= 8.0.0, < 8.0.14 | 8.0.14 | Mar 11, 2025 | Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. | |
| CVE-2024-21404 | Hig | 7.5 | >= 6.0.0, < 6.0.27 | 6.0.27 | Feb 13, 2024 | .NET Denial of Service Vulnerability | |
| CVE-2024-21386 | Hig | 7.5 | >= 6.0.0, < 6.0.27 | 6.0.27 | Feb 13, 2024 | .NET Denial of Service Vulnerability | |
| CVE-2023-36558 | Med | 6.2 | >= 6.0.0, < 6.0.25 | 6.0.25 | Nov 14, 2023 | ASP.NET Core Security Feature Bypass Vulnerability | |
| CVE-2023-36038 | Hig | 8.2 | >= 8.0.0, < 8.0.1 | 8.0.1 | Nov 14, 2023 | ASP.NET Core Denial of Service Vulnerability | |
| CVE-2023-44487 | Hig | 7.5 | KEV | >= 6.0.0, < 6.0.23 | 6.0.23 | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-38180 | Hig | 7.5 | KEV | >= 2.1.0, < 2.1.40 | 2.1.40 | Aug 8, 2023 | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2023-35391 | Med | 6.2 | >= 2.1.0, < 2.1.40 | 2.1.40 | Aug 8, 2023 | ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability | |
| CVE-2021-43877 | Hig | 8.8 | >= 3.1.0, < 3.1.1 | 3.1.1 | Dec 15, 2021 | ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability | |
| CVE-2021-34532 | Med | 5.5 | >= 2.1.0, < 2.1.3 | 2.1.3 | Aug 12, 2021 | ASP.NET Core and Visual Studio Information Disclosure Vulnerability | |
| CVE-2021-1723 | Hig | 7.5 | >= 3.1.0, < 3.1.11 | 3.1.11 | Jan 12, 2021 | ASP.NET Core and Visual Studio Denial of Service Vulnerability | |
| CVE-2020-1045 | Hig | 7.5 | >= 3.1.0, < 3.1.8 | 3.1.8 | Sep 11, 2020 | A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names. The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.< | |
| CVE-2020-1597 | Hig | 7.5 | >= 2.1.0, < 2.1.1 | 2.1.1 | Aug 17, 2020 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without auth |
- affected >= 8.0.0, < 8.0.28fixed 8.0.28
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.28fixed 8.0.28
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
- affected >= 10.0.0, < 10.0.7fixed 10.0.7
Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network.
- affected >= 8.0.0, < 8.0.25fixed 8.0.25
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
- affected >= 2.3.0, < 2.3.6fixed 2.3.6
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security feature over a network.
- affected >= 6.0.0, < 7.0.18fixed 7.0.18
Weak authentication in EOL ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. NOTE: This CVE affects only End Of Life (EOL) software components. The vendor, Microsoft, has indicated there will be no future updates nor support provided upon inquiry
- affected >= 8.0.0, < 8.0.15fixed 8.0.15
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
- affected >= 8.0.0, < 8.0.14fixed 8.0.14
Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.
- affected >= 6.0.0, < 6.0.27fixed 6.0.27
.NET Denial of Service Vulnerability
- affected >= 6.0.0, < 6.0.27fixed 6.0.27
.NET Denial of Service Vulnerability
- affected >= 6.0.0, < 6.0.25fixed 6.0.25
ASP.NET Core Security Feature Bypass Vulnerability
- affected >= 8.0.0, < 8.0.1fixed 8.0.1
ASP.NET Core Denial of Service Vulnerability
- affected >= 6.0.0, < 6.0.23fixed 6.0.23
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- affected >= 2.1.0, < 2.1.40fixed 2.1.40
.NET and Visual Studio Denial of Service Vulnerability
- affected >= 2.1.0, < 2.1.40fixed 2.1.40
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
- affected >= 3.1.0, < 3.1.1fixed 3.1.1
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
- affected >= 2.1.0, < 2.1.3fixed 2.1.3
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
- affected >= 3.1.0, < 3.1.11fixed 3.1.11
ASP.NET Core and Visual Studio Denial of Service Vulnerability
- affected >= 3.1.0, < 3.1.8fixed 3.1.8
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names. The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.<
- affected >= 2.1.0, < 2.1.1fixed 2.1.1
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without auth
Page 1 of 2