CVE-2025-26682

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 770

Summary

CVE-2025-26682 is a denial-of-service vulnerability affecting ASP.NET Core. The issue permits an attacker to exhaust resources without limitation or throttling, leading to a network service disruption. This vulnerability can be exploited remotely, making it a significant security concern for organizations using ASP.NET Core applications. By consuming resources beyond the capacity of the system, an attacker can cause the application to become unresponsive or unavailable, resulting in a denial-of-service condition. It is essential for users to update their ASP.NET Core installations to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share