Description
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to allocate resources without limits or throttling in ASP.NET Core, causing unbounded consumption of server resources and resulting in denial of service. This flaw can be triggered by unauthorized network traffic, preventing legitimate users from accessing the affected service.

Affected Systems

The affected product is Microsoft ASP.NET Core OData. No specific version ranges are provided in the advisory; organizations using this component should verify if they are affected by consulting the Microsoft Security Response Center or the update guide.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate to high severity. Because the exploit path requires only network access and no authentication, an unauthenticated attacker can initiate the resource exhaustion loop. While EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, the potential impact of crippling an entire application remains significant, warranting prompt remediation.

Generated by OpenCVE AI on September 8, 2026 at 18:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor–supplied security update for Microsoft ASP.NET Core OData
  • If the update is not yet available, configure resource limits or throttle settings to constrain allocation per request
  • Set up application health monitoring and network rate limiting to detect and mitigate sudden spikes in resource consumption

Generated by OpenCVE AI on September 8, 2026 at 18:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Title ASP.NET Core Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft .asp.netcore
Weaknesses CWE-770
CPEs cpe:2.3:a:microsoft:.Asp.NetCore:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .asp.netcore
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .asp.netcore
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T18:39:22.269Z

Reserved: 2026-06-23T18:29:51.054Z

Link: CVE-2026-57099

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:17:43.057

Modified: 2026-09-08T18:39:13.460

Link: CVE-2026-57099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:00:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling