Junglewise Threat Intelligence

CVE-2026-57099: Microsoft ASP.NET Core resource exhaustion denial of service

CVE-2026-57099 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Microsoft Asp.Net Core. Vendors: Microsoft.

Executive brief

ASP.NET Core is a web framework used to build web applications and APIs. A flaw in how it manages computational resources allows unauthenticated attackers to send specially crafted network requests that exhaust server resources, causing the application to become unavailable to legitimate users.

Technical details

ASP.NET Core contains an allocation of resources without limits or throttling vulnerability that enables a denial-of-service condition. An unauthenticated attacker can trigger excessive resource consumption by sending network requests to an affected server. No authentication or special preconditions are required; the vulnerability is reachable directly over the network. An attacker can crash or render the application unresponsive, disrupting service availability. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft ASP.NET Core

Timeline

  • 2026-09-08: disclosed

References

Related threats