May 2026: ASP.NET Core Denial of Service Vulnerability
CVE-2026-42899 Published on May 12, 2026

ASP.NET Core Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Vendor Advisory NVD

Weakness Type

What is an Infinite Loop Vulnerability?

The program contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop. If the loop can be influenced by an attacker, this weakness could allow attackers to consume excessive resources such as CPU or memory.

CVE-2026-42899 has been classified to as an Infinite Loop vulnerability or weakness.


Products Associated with CVE-2026-42899

Want to know whenever a new CVE is published for Microsoft Net? stack.watch will email you.

 

Affected Versions

Microsoft .NET 10.0: Microsoft .NET 8.0: Microsoft .NET 9.0: