Description
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application.
The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application.
The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2252 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. |
Github GHSA |
GHSA-3w5p-jhp5-c29q | .NET Core & .NET Framework Denial of Service Vulnerability |
References
History
Wed, 19 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. |
| Title | dotnet: Denial of service via untrusted input | .NET Core & .NET Framework Denial of Service Vulnerability |
| CPEs | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:*:sp2:*:*:*:*:*:* cpe:2.3:a:microsoft:.net_framework:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:powershell_core:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* |
|
| References |
|
Subscriptions
Microsoft
Subscribe
.net
Subscribe
.net Core
Subscribe
.net Framework
Subscribe
Powershell
Subscribe
Powershell Core
Subscribe
Visual Studio 2017
Subscribe
Visual Studio 2019
Subscribe
Windows 10
Subscribe
Windows 7
Subscribe
Windows 8.1
Subscribe
Windows Rt 8.1
Subscribe
Windows Server 2008
Subscribe
Windows Server 2012
Subscribe
Windows Server 2016
Subscribe
Windows Server 2019
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Dotnet
Subscribe
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-19T16:34:04.566Z
Reserved: 2019-11-04T00:00:00.000Z
Link: CVE-2020-1108
No data.
Status : Modified
Published: 2020-05-21T23:15:14.867
Modified: 2026-08-19T17:17:18.240
Link: CVE-2020-1108
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-190
Integer Overflow or Wraparound
-
CWE-20
Improper Input Validation
- NVD-CWE-noinfo
EUVD
Github GHSA