GHSA-6px8-22w5-w334
GitHub Security Advisory
Denial of service in ASP.NET Core
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548.
Affected Packages
NuGet
Microsoft.AspNetCore.WebSockets
Affected versions:
2.2.0
(fixed in 2.2.1)
NuGet
Microsoft.AspNetCore.WebSockets
Affected versions:
2.1.0
(fixed in 2.1.7)
NuGet
Microsoft.AspNetCore.Server.Kestrel.Core
Affected versions:
2.1.0
(fixed in 2.1.7)
NuGet
System.Net.WebSockets.WebSocketProtocol
Affected versions:
4.5.0
(fixed in 4.5.3)
NuGet
Microsoft.NETCore.App
Affected versions:
2.2.0
(fixed in 2.2.1)
NuGet
Microsoft.NETCore.App
Affected versions:
2.1.0
(fixed in 2.1.7)
NuGet
Microsoft.AspNetCore.App
Affected versions:
2.2.0
(fixed in 2.2.1)
NuGet
Microsoft.AspNetCore.App
Affected versions:
2.1.0
(fixed in 2.1.7)
NuGet
Microsoft.AspNetCore.All
Affected versions:
2.2.0
(fixed in 2.2.1)
NuGet
Microsoft.AspNetCore.All
Affected versions:
2.1.0
(fixed in 2.1.7)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: June 12, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.