Loading HuntDB...

GHSA-j378-6mmw-hqfr

GitHub Security Advisory

Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.

Affected Packages

NuGet Microsoft.AspNetCore.All
Affected versions: 2.1.0 (fixed in 2.1.4)
NuGet Microsoft.AspNetCore.App
Affected versions: 2.1.0 (fixed in 2.1.4)
NuGet System.IO.Pipelines
Affected versions: 4.5.0 (fixed in 4.5.1)

Related CVEs

Key Information

GHSA ID
GHSA-j378-6mmw-hqfr
Published
October 16, 2018 7:56 PM
Last Modified
October 26, 2022 6:56 PM
CVSS Score
7.5 /10
Primary Ecosystem
NuGet
Primary Package
Microsoft.AspNetCore.All
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.