Impact
The vulnerability resides in the .NET runtime’s lack of limits or throttling when allocating resources. An attacker can trigger uncontrolled memory or CPU consumption by sending specially crafted requests to a vulnerable application, consuming available system resources and disabling legitimate processing, which results in a denial of service. This flaw is classified as CWE-770, indicating excessive resource consumption.
Affected Systems
The flaw impacts the Microsoft .NET runtime series, including .NET 10.0, .NET 8.0, and .NET 9.0, as well as several .NET Framework releases (3.5 through 4.8.1). Additionally, Visual Studio 2022 versions 17.12, 17.14, and the upcoming Visual Studio 2026 release 18.7 are affected, as they embed the vulnerable runtime libraries.
Risk and Exploitability
The CVSS score of 7.5 signals a moderate‑to‑high severity. The EPSS score of less than 1% indicates that exploitation is currently rare, and the flaw is not listed in CISA’s KEV catalog. The attack vector is presumed to be network‑based: an unauthenticated remote attacker introduces crafted payloads to a vulnerable application, leading to resource exhaustion that renders the service unavailable.
OpenCVE Enrichment
Github GHSA
Ubuntu USN