Impact
The vulnerability stems from an uncontrolled allocation of resources in ASP.NET Core's OData implementation. Because limits or throttling mechanisms are absent, an attacker can consume a disproportionate amount of server resources, causing legitimate requests to fail and potentially rendering the application completely unavailable. This flaw is identified as a resource‑exhaustion weakness (CWE‑770).
Affected Systems
The flaw affects Microsoft products that use the AspNet.OData and AspNetCore.OData libraries. No specific version information is provided, so all installations using these libraries are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high‑severity impact on availability. The EPSS score of less than 1% suggests that exploitation is presently rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over a network, with an unauthenticated attacker targeting the OData endpoints to trigger excessive resource consumption.
OpenCVE Enrichment