CVE-2026-26130

Description

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.586

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2026-26130 are fixed in ASP.NET Core Runtime (8.0) (x86) 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in ASP.NET Core Runtime (8.0) (x64) 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in ASP.NET Core Runtime (9.0) (x86) 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in ASP.NET Core Runtime (9.0) (x64) 9.0.14Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Desktop Runtime (9.0) (x64) 9.0.14Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Desktop Runtime (9.0) (x86) 9.0.14Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Runtime (9.0) (x64) 9.0.14Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Runtime (9.0) (x86) 9.0.14Windows
Vulnerabilities CVE-2026-26127 are fixed in ASP.NET Core Runtime (9.0) (x64) 9.0.14Windows
Vulnerabilities CVE-2026-26127 are fixed in ASP.NET Core Runtime (9.0) (x86) 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in ASP.NET Core Runtime (10.0) (x64) 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in ASP.NET Core Runtime (10.0) (x86) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Desktop Runtime (10.0) (x64) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Desktop Runtime (10.0) (x86) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Runtime (10.0) (x64) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in Dot NET Runtime (10.0) (x86) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in ASP.NET Core Runtime (10.0) (x64) 10.0.4Windows
Vulnerabilities CVE-2026-26127 are fixed in ASP.NET Core Runtime (10.0) (x86) 10.0.4Windows
ASP.NET Core Denial of Service Vulnerability for .NET Hosting (10.0.4) (KB5081276) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x64) (10.0.200) (KB5081276) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x86) (10.0.200) (KB5081276) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x64) (10.0.104) (KB5081276) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x86) (10.0.104) (KB5081276) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET Hosting (9.0.14) (KB5081278) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x64) (9.0.312) (KB5081278) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x86) (9.0.312) (KB5081278) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x64) (9.0.115) (KB5081278) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x86) (9.0.115) (KB5081278) (CVE-2026-26127)Windows
ASP.NET Core Denial of Service Vulnerability for .NET Hosting (8.0.25) (KB5081277)Windows
ASP.NET Core Denial of Service Vulnerability for .NET Desktop Runtime (x64) (8.0.25) (KB5081277)Windows
ASP.NET Core Denial of Service Vulnerability for .NET Desktop Runtime (x86) (8.0.25) (KB5081277)Windows
ASP.NET Core Denial of Service Vulnerability for .NET Runtime (x64) (8.0.25) (KB5081277)Windows
ASP.NET Core Denial of Service Vulnerability for .NET Runtime (x86) (8.0.25) (KB5081277)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x64) (8.0.419) (KB5081277)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x86) (8.0.419) (KB5081277)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x64) (8.0.125) (KB5081277)Windows
ASP.NET Core Denial of Service Vulnerability for .NET SDK (x86) (8.0.125) (KB5081277)Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-arm 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-arm 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-arm 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-musl-arm 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-musl-arm 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-musl-arm 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.win-arm 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.win-arm 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.win-arm 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-arm64 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-arm64 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-arm64 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-x64 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-x64 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-x64 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-x64 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-x64 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-x64 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-x64 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-x64 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-x64 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x64 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x64 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x64 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x86 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x86 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x86 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-arm64 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-arm64 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-arm64 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-arm64 8.0.25Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-arm64 9.0.14Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-arm64 10.0.4Windows
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-arm for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-arm for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-arm for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-musl-arm for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-musl-arm for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.linux-musl-arm for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.win-arm for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.win-arm for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget-Microsoft.AspNetCore.App.Runtime.win-arm for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-arm64 for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-arm64 for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-arm64 for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-x64 for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-x64 for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-x64 for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-x64 for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-x64 for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-x64 for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-x64 for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-x64 for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-x64 for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x64 for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x64 for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x64 for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x86 for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x86 for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-x86 for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-arm64 for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-arm64 for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.win-arm64 for Linux 10.0.4Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-arm64 for Linux 8.0.25Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-arm64 for Linux 9.0.14Linux
Vulnerabilities CVE-2026-26130 are fixed in Nuget - Microsoft.AspNetCore.App.Runtime.osx-arm64 for Linux 10.0.4Linux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-43605Update for AspNet Core (x86) (8.0.25) (KB5081277)
PATCH-43604Update for AspNet Core (x64) (8.0.25) (KB5081277)
PATCH-43616Update for AspNet Core (x86) (9.0.14) (KB5081278) (CVE-2026-26127)
PATCH-43615Update for AspNet Core (x64) (9.0.14) (KB5081278) (CVE-2026-26127)
PATCH-43617Update for .NET Desktop Runtime (x64) (9.0.14) (KB5081278) (CVE-2026-26127)
PATCH-43618Update for .NET Desktop Runtime (x86) (9.0.14) (KB5081278) (CVE-2026-26127)
PATCH-43619Update for .NET Runtime (x64) (9.0.14) (KB5081278) (CVE-2026-26127)
PATCH-43620Update for .NET Runtime (x86) (9.0.14) (KB5081278) (CVE-2026-26127)
PATCH-43615Update for AspNet Core (x64) (9.0.14) (KB5081278) (CVE-2026-26127)
PATCH-43616Update for AspNet Core (x86) (9.0.14) (KB5081278) (CVE-2026-26127)
PATCH-43593Update for AspNet Core (x64) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43594Update for AspNet Core (x86) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43595Update for .NET Desktop Runtime (x64) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43596Update for .NET Desktop Runtime (x86) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43597Update for .NET Runtime (x64) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43598Update for .NET Runtime (x86) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43593Update for AspNet Core (x64) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43594Update for AspNet Core (x86) (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43592Update for .NET Hosting (10.0.4) (KB5081276) (CVE-2026-26127)
PATCH-43599Update for .NET SDK (x64) (10.0.200) (KB5081276) (CVE-2026-26127)
PATCH-43600Update for .NET SDK (x86) (10.0.200) (KB5081276) (CVE-2026-26127)
PATCH-43601Update for .NET SDK (x64) (10.0.104) (KB5081276) (CVE-2026-26127)
PATCH-43602Update for .NET SDK (x86) (10.0.104) (KB5081276) (CVE-2026-26127)
PATCH-43614Update for .NET Hosting (9.0.14) (KB5081278) (CVE-2026-26127)
PATCH-43621Update for .NET SDK (x64) (9.0.312) (KB5081278) (CVE-2026-26127)
PATCH-43622Update for .NET SDK (x86) (9.0.312) (KB5081278) (CVE-2026-26127)
PATCH-43623Update for .NET SDK (x64) (9.0.115) (KB5081278) (CVE-2026-26127)
PATCH-43624Update for .NET SDK (x86) (9.0.115) (KB5081278) (CVE-2026-26127)
PATCH-43603Update for .NET Hosting (8.0.25) (KB5081277)
PATCH-43606Update for .NET Desktop Runtime (x64) (8.0.25) (KB5081277)
PATCH-43607Update for .NET Desktop Runtime (x86) (8.0.25) (KB5081277)
PATCH-43608Update for .NET Runtime (x64) (8.0.25) (KB5081277)
PATCH-43609Update for .NET Runtime (x86) (8.0.25) (KB5081277)
PATCH-43610Update for .NET SDK (x64) (8.0.419) (KB5081277)
PATCH-43611Update for .NET SDK (x86) (8.0.419) (KB5081277)
PATCH-43612Update for .NET SDK (x64) (8.0.125) (KB5081277)
PATCH-43613Update for .NET SDK (x86) (8.0.125) (KB5081277)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234