Sep 2026: ASP.NET Core Denial of Service Vulnerability
CVE-2026-69304 Published on September 8, 2026

ASP.NET Core Denial of Service Vulnerability
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Vendor Advisory NVD

Weakness Type

What is a Data Amplification Vulnerability?

The software does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output. An example of data amplification is a "decompression bomb," a small ZIP file that can produce a large amount of data when it is decompressed.

CVE-2026-69304 has been classified to as a Data Amplification vulnerability or weakness.


Products Associated with CVE-2026-69304

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 

Affected Versions

Microsoft .NET 10.0: Microsoft .NET 8.0: Microsoft .NET 9.0: Microsoft ASP.NET Core 10.0: Microsoft ASP.NET Core 11.0: Microsoft ASP.NET Core 8.0: Microsoft ASP.NET Core 9.0: Microsoft Visual Studio 2022 version 17.14: Microsoft Visual Studio 2026 version 18.9: