Description
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
Published: 2026-07-14
Score: 7.5 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A type‑confusion flaw in .NET Core permits an attacker to trigger a denial‑of‑service condition by sending specially crafted data over the network. The incompatible type, resulting in an exception that may to legitimate users.

Affected Systems

The flaw affects Microsoft .NET 10.0, .NET 9.0, and .NET 8.0. Any installation of these runtimes that processes untrusted network data is potentially vulnerable; the exact patch level is not specified in the input, but the advisory references a security update for all listed versions.

Risk and Exploitability

With a CVSS score of 7.5 and an EPSS probability of 0.01105 (~1.11 %), the risk of exploitation is moderate but present. The vulnerability is not listed in CISA KEV, suggesting no confirmed widespread exploitation yet. Based on the description it is inferred that an unauthorized attacker can exploit the sending exploitation would cause application crashes or hangs, leading to service interruption for affected users.

Generated by OpenCVE AI on July 31, 2026 at 06:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft .NET security update for the affected version, as referenced in the Microsoft Security Response Center advisory.
  • If patching cannot be performed immediately, restrict external network access to the application or service so that only trusted traffic can reach the vulnerable component, reducing the likelihood of a successful denial‑of‑service attack.
  • Implement application monitoring and graceful handling of anomalous resource access to detect and mitigate crashes caused by type‑confusion errors.

Generated by OpenCVE AI on July 31, 2026 at 06:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rp2p-6cmp-jxj9 Microsoft Security Advisory CVE-2026-57108 – .NET Denial of Service Vulnerability
Ubuntu USN Ubuntu USN USN-8553-1 .NET vulnerabilities
History

Sat, 18 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat hummingbird
CPEs cpe:/a:redhat:hummingbird:1
Vendors & Products Redhat
Redhat hummingbird
References
Metrics threat_severity

None

threat_severity

Important


Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
Title .NET Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft .net
Weaknesses CWE-843
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net
Redhat Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:58:07.407Z

Reserved: 2026-06-23T18:29:51.054Z

Link: CVE-2026-57108

cve-icon Vulnrichment

Updated: 2026-07-14T18:01:20.478Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T17:09:39Z

Links: CVE-2026-57108 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T06:30:18Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')