Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45591

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

A flaw was found in ASP.NET Core SignalR and Blazor Server. A remote attacker could send a specially crafted MessagePack payload containing deeply nested arrays that trigger excessive recursion and cause a stack overflow. This issue may result in application termination and a denial of service condition

Отчет

This vulnerability affects the MessagePack hub protocol implementation used by ASP.NET Core SignalR and Blazor Server. Red Hat Product Security has assessed this issue as an Important severity vulnerability. The flaw occurs when processing deeply nested MessagePack arrays supplied by a remote attacker. Insufficient validation of message nesting depth may cause excessive recursion and trigger a stack overflow condition during message processing. Successful exploitation could allow an unauthenticated remote attacker to cause the affected application or service to terminate unexpectedly, resulting in a denial of service condition.

Меры по смягчению последствий

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2487224dotnet: ASP.NET Core: Denial of Service via uncontrolled resource consumption

EPSS

Процентиль: 83%
0.0243
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
nvd
около 2 месяцев назад

Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.

CVSS3: 7.5
msrc
около 2 месяцев назад

ASP.NET Core Denial of Service Vulnerability

CVSS3: 7.5
github
около 2 месяцев назад

Microsoft Security Advisory CVE-2026-45591 – ASP.NET Core Denial of Service Vulnerability

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость программных платформ .NET, ASP.NET и Microsoft Visual Studio, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 83%
0.0243
Низкий

7.5 High

CVSS3