Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-26682

Опубликовано: 08 апр. 2025
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

A flaw was found in dotnet. Improper use of the HTTP/3 protocol allows an unauthorized remote attacker to cause an allocation of resources without limits or throttling in ASP.NET Core, resulting in a denial of service.

Отчет

This issue can only be exploited when support for the HTTP/3 protocol is enabled. The .NET packages shipped in Red Hat Enterprise Linux do not support the HTTP/3 protocol. Therefore, Red Hat products are not affected by this vulnerability.

.NET 6.0 for RHEL-8, RHEL-9 and RHIVOS has reached its End of Life as of November 12, 2024, and is no longer supported. For additional information about lifecycle for .NET on Red Hat Enterprise Linux, please refer to: https://access.redhat.com/support/policy/updates/net-core.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dotnet8.0Not affected
Red Hat Enterprise Linux 10dotnet9.0Not affected
Red Hat Enterprise Linux 8dotnet8.0Not affected
Red Hat Enterprise Linux 8dotnet9.0Not affected
Red Hat Enterprise Linux 9dotnet6.0Out of support scope
Red Hat Enterprise Linux 9dotnet7.0Out of support scope
Red Hat Enterprise Linux 9dotnet8.0Not affected
Red Hat Enterprise Linux 9dotnet9.0Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2357945dotnet: .NET: ASP.NET Core denial of service with HTTP/3

EPSS

Процентиль: 98%
0.47033
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 месяцев назад

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
nvd
12 месяцев назад

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
msrc
12 месяцев назад

ASP.NET Core and Visual Studio Denial of Service Vulnerability

CVSS3: 7.5
github
12 месяцев назад

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
fstec
12 месяцев назад

Уязвимость программной платформы ASP.NET Core и средства разработки программного обеспечения Microsoft Visual Studio, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 98%
0.47033
Средний

7.5 High

CVSS3