Sep 2026: ASP.NET Core Denial of Service Vulnerability
CVE-2026-69304 Published on September 8, 2026
ASP.NET Core Denial of Service Vulnerability
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Weakness Type
What is a Data Amplification Vulnerability?
The software does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output. An example of data amplification is a "decompression bomb," a small ZIP file that can produce a large amount of data when it is decompressed.
CVE-2026-69304 has been classified to as a Data Amplification vulnerability or weakness.
Products Associated with CVE-2026-69304
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft .NET 10.0:- Version 10.0.0 and below 10.0.12 is affected.
- Version 8.0.0 and below 8.0.31 is affected.
- Version 9.0.0 and below 9.0.20 is affected.
- Version 10.0 and below 10.0.12 is affected.
- Version 11.0 and below 11.0 RC1 is affected.
- Version 8.0 and below 8.0.31 is affected.
- Version 9.0 and below 9.0.20 is affected.
- Version 17.14.0 and below 17.14.40 is affected.
- Version 18.9.0 and below 18.9.3 is affected.