Description
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability stems from improper handling of highly compressed data in ASP.NET Core. When an attacker sends a compressed payload that expands to a substantially larger size on the server, the application’s memory and processing resources can be exhausted, leading to a denial‑of‑service condition for the web server and any clients awaiting a response. No confidentiality or integrity compromise is reported.

Affected Systems

Affected installations include Microsoft .NET from version 8.0 to 11.0 and ASP.NET Core from 8.0 to 11.0. The issue also impacts Microsoft Visual Studio 2022 version 17.14 and Microsoft Visual Studio 2026 version 18.9. All of these rely on the same ASP.NET Core framework that processes incoming HTTP requests.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The exploit probability metric is not available, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack path would involve an unauthenticated network attacker sending a large compressed payload to the vulnerable application. While no active exploits are reported, the lack of restriction on request size creates a measurable risk to availability.

Generated by OpenCVE AI on September 8, 2026 at 19:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest security update for Microsoft .NET and ASP.NET Core that addresses compression handling.
  • If an update is not yet available, enforce a maximum request size or disable handling of compressed payloads at the application or web‑server level to limit amplification.
  • Enable monitoring of inbound traffic for unusually large or compressed data packets and alert on repeated attempts to trigger resource exhaustion.

Generated by OpenCVE AI on September 8, 2026 at 19:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8cp2-47hg-mfgh Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
History

Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026
Vendors & Products Microsoft microsoft Visual Studio 2022
Microsoft microsoft Visual Studio 2026

Wed, 09 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Title ASP.NET Core Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft .net
Microsoft asp.net Core
Microsoft visual Studio 2022
Microsoft visual Studio 2026
Weaknesses CWE-409
CPEs cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:visual_studio_2026:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .net
Microsoft asp.net Core
Microsoft visual Studio 2022
Microsoft visual Studio 2026
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .net Asp.net Core Microsoft Visual Studio 2022 Microsoft Visual Studio 2026 Visual Studio 2022 Visual Studio 2026
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:37:36.275Z

Reserved: 2026-08-03T20:46:07.440Z

Link: CVE-2026-69304

cve-icon Vulnrichment

Updated: 2026-09-08T19:34:05.903Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:46.347

Modified: 2026-09-08T20:17:46.873

Link: CVE-2026-69304

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T20:52:26Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)