Impact
ASP.NET Core can allocate resources without limits or throttling, which allows an unauthorized attacker to cause a denial of service across a network. The vulnerability is a classic case of uncontrolled resource consumption, identified as CWE-770. Resulting DoS can render the targeted web application unavailable to legitimate users.
Affected Systems
Microsoft .NET 8.0, 9.0, and 10.0 are impacted. These versions can be found on the Microsoft ".NET" platform and should be evaluated for deployment of any updates or patches. In addition, RedHat Hummingbird version 1 is affected and should receive its corresponding update.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of about 1% indicates a low exploitation probability at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network-based, where an attacker can send crafted requests to trigger excessive resource consumption.
OpenCVE Enrichment
Github GHSA