Description
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Score: 7.5 High
EPSS: 1.2% Low
KEV: No
Impact: Denial of Service
Action: Patch ASAP
AI Analysis

Impact

The vulnerability allows an attacker to allocate resources without limits or throttling in ASP.NET Core, causing unbounded consumption of server resources and resulting in denial of service. This flaw can be triggered by unauthorized network traffic, preventing legitimate users from accessing the affected service.

Affected Systems

The affected product is Microsoft ASP.NET Core OData. No specific version ranges are provided in the advisory; organizations using this component should verify if they are affected by consulting the Microsoft Security Response Center or the update guide.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate to high severity. Because the exploit path requires only network access and no authentication, an unauthenticated attacker can initiate the resource exhaustion loop. While EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, the potential impact of crippling an entire application remains significant, warranting prompt remediation.

Generated by OpenCVE AI on September 8, 2026 at 18:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor–supplied security update for Microsoft ASP.NET Core OData
  • If the update is not yet available, configure resource limits or throttle settings to constrain allocation per request
  • Set up application health monitoring and network rate limiting to detect and mitigate sudden spikes in resource consumption

Generated by OpenCVE AI on September 8, 2026 at 18:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft .asp.netcore
Vendors & Products Microsoft .asp.netcore

Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Title ASP.NET Core Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft .asp.netcore
Weaknesses CWE-770
CPEs cpe:2.3:a:microsoft:.Asp.NetCore:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .asp.netcore
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .asp.netcore .asp.netcore
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:38:58.313Z

Reserved: 2026-06-23T18:29:51.054Z

Link: CVE-2026-57099

cve-icon Vulnrichment

Updated: 2026-09-08T20:45:22.200Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:17:43.057

Modified: 2026-09-08T21:18:14.133

Link: CVE-2026-57099

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-08T17:19:11Z

Links: CVE-2026-57099 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:00:12Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling