PT-2026-40264 · Microsoft+4 · Asp.Net Core+4

·

CVE-2026-42899

·

Published

2026-05-12

·

Updated

2026-06-08

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ASP.NET Core versions prior to 8.0.27 ASP.NET Core versions prior to 9.0.16 ASP.NET Core versions prior to 10.0.8
Description An unauthorized attacker can cause a denial of service over a network due to a loop with an unreachable exit condition, resulting in an infinite loop. This issue impacts multiple runtime packages across Linux, Windows, and macOS platforms.
Recommendations Update to version 8.0.27 or later. Update to version 9.0.16 or later. Update to version 10.0.8 or later.

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:21286
ALSA-2026:21291
ALSA-2026:21293
ALSA-2026:21294
ALSA-2026:21295
ALSA-2026:21296
ALSA-2026:21297
ALSA-2026:21754
ALSA-2026:22145
BDU:2026-06767
BIT-DOTNET-2026-42899
BIT-DOTNET-SDK-2026-42899
CVE-2026-42899
GHSA-9V76-4QCC-FRGH
RHSA-2026:17464
RHSA-2026:17527
RHSA-2026:17682
RHSA-2026:21286
RHSA-2026:21291
RHSA-2026:21293
RHSA-2026:21294
RHSA-2026:21295
RHSA-2026:21296
RHSA-2026:21297
RHSA-2026:21754
RHSA-2026:22145
RHSA-2026:24332
RHSA-2026:24333
RHSA-2026:24334
RHSA-2026:24335
RHSA-2026:24336
USN-8298-1

Affected Products

Asp.Net Core
Linuxmint
Red Os
Rocky Linux
Ubuntu