Impact
The vulnerability stems from improper handling of highly compressed data in ASP.NET Core. When an attacker sends a compressed payload that expands to a substantially larger size on the server, the application’s memory and processing resources can be exhausted, leading to a denial‑of‑service condition for the web server and any clients awaiting a response. No confidentiality or integrity compromise is reported.
Affected Systems
Affected installations include Microsoft .NET from version 8.0 to 11.0 and ASP.NET Core from 8.0 to 11.0. The issue also impacts Microsoft Visual Studio 2022 version 17.14 and Microsoft Visual Studio 2026 version 18.9. All of these rely on the same ASP.NET Core framework that processes incoming HTTP requests.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The exploit probability metric is not available, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack path would involve an unauthenticated network attacker sending a large compressed payload to the vulnerable application. While no active exploits are reported, the lack of restriction on request size creates a measurable risk to availability.
OpenCVE Enrichment
Github GHSA