Loading HuntDB...

GHSA-f9jc-rrm2-pmfg

GitHub Security Advisory

Denial of service in ASP.NET Core

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly handling web requests, aka ".NET CORE Denial Of Service Vulnerability".

Affected Packages

NuGet Microsoft.AspNetCore.Server.WebListener
Affected versions: 1.0.0 (fixed in 1.0.6)
NuGet Microsoft.AspNetCore.Server.WebListener
Affected versions: 1.1.0 (fixed in 1.1.4)
NuGet Microsoft.Net.Http.Server
Affected versions: 1.0.0 (fixed in 1.0.6)
NuGet Microsoft.Net.Http.Server
Affected versions: 1.1.0 (fixed in 1.1.4)
NuGet Microsoft.AspNetCore.Server.HttpSys
Affected versions: 2.0.0 (fixed in 2.0.2)

Related CVEs

Key Information

GHSA ID
GHSA-f9jc-rrm2-pmfg
Published
May 13, 2022 1:42 AM
Last Modified
July 8, 2022 7:22 PM
CVSS Score
7.5 /10
Primary Ecosystem
NuGet
Primary Package
Microsoft.AspNetCore.Server.WebListener
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 17, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.