GHSA-f9jc-rrm2-pmfg
GitHub Security Advisory
Denial of service in ASP.NET Core
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly handling web requests, aka ".NET CORE Denial Of Service Vulnerability".
Affected Packages
NuGet
Microsoft.AspNetCore.Server.WebListener
Affected versions:
1.0.0
(fixed in 1.0.6)
NuGet
Microsoft.AspNetCore.Server.WebListener
Affected versions:
1.1.0
(fixed in 1.1.4)
NuGet
Microsoft.Net.Http.Server
Affected versions:
1.0.0
(fixed in 1.0.6)
NuGet
Microsoft.Net.Http.Server
Affected versions:
1.1.0
(fixed in 1.1.4)
NuGet
Microsoft.AspNetCore.Server.HttpSys
Affected versions:
2.0.0
(fixed in 2.0.2)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: June 17, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.