Impact
This vulnerability is an unbounded resource allocation flaw in the .NET runtime. Allocation of resources without limits or throttling allows an unauthorized attacker to request large amounts of memory, exhausting system resources and leading to a denial of service over a network. The flaw is classified as CWE-770, Resource Exhaustion.
Affected Systems
Microsoft .NET Framework versions 8.0, 9.0, and 10.0 are affected, along with Microsoft Visual Studio 2022 versions 17.12 and 17.14, and Microsoft Visual Studio 2026 version 18.7. All of these products are impacted by the unbounded allocation behavior.
Risk and Exploitability
The CVSS score of 7.5 places this flaw in the high‑moderate severity range, while the EPSS score of less than 1% indicates that exploitation is expected to be infrequent. The flaw is not listed in CISA's KEV catalog. Attackers would need to deliver a crafted request over a network to the vulnerable .NET application or service, and then repeatedly trigger large allocations until the system runs out of memory or the process is killed, resulting in a denial of service.
OpenCVE Enrichment
Github GHSA
Ubuntu USN