CVE-2026-26130Disclosure(microsoft / asp.net_core)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch microsoft asp.net_core systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • asp.net_core

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • False Positive: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-12); latest day: 2
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
asp.net_core

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-03-10: 1Mentions · 2026-03-12: 2Mentions · 2026-03-16: 1Mentions · 2026-03-18: 1Mentions · 2026-03-20: 2Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-16: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-20: 103-1003-1203-1603-1803-20
Signal classification4 categories
Disclosure
342.9%
General
228.6%
False Positive
114.3%
Patch
114.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-101
General1
2026-03-122
Disclosure2
2026-03-161
Disclosure1
2026-03-181
General1
2026-03-202
False Positive1Patch1
Full discourse7 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔐 Critical .NET 10.0 Security Update for Fedora 43: CVE-2026-26130 (http://ASP.NET Core DoS) . If you're running .NET applications on #Fedora 43. Read more: 👉 https://tinyurl.com/37p329k3 #Security https://t.co/G8apwc12FT

    Post summary

    Fedora 43 users running .NET 10.0 should apply the critical security update addressing CVE‑2026‑26130, a denial‑of‑service flaw in ASP.NET Core.

    0000089
    1.5K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    False Positive

    🔍 Lambda Watchdog detected that CVE-2026-26130 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/448 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post reports that CVE‑2026‑26130 has been removed from the latest AWS Lambda base images, indicating the vulnerability is no longer present.

    0000031
    31 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-26130: http://ASP.NET Core Unbounded Resource Allocation - What It Means for Your Business and How to Respond https://hubs.li/Q047k6l90

    Post summary

    The snippet refers to CVE‑2026‑26130 as an unbounded resource allocation issue but offers no concrete evidence of exploits, patches, or active attacks.

    0000022
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26130 Allocation of resources without limits or throttling in http://ASP.NET Core allows an unauthorized attacker to deny service over a network. https://www.cve.org/CVERecord?id=CVE-2026-26130

    Post summary

    The text discloses a new CVE (CVE-2026-26130) affecting ASP.NET Core, describing a resource‑exhaustion vulnerability that could enable unauthorized denial‑of‑service attacks.

    00000163
    56.7K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-26130 impacts http://Microsoft.AspNetCore.App.Runtime.linux-x64 in 4 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/448 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE (CVE‑2026‑26130) affecting Microsoft.AspNetCore.App.Runtime.linux‑x64 in several AWS Lambda base images has been reported, but no exploitation or remediation details are provided.

    0000026
    31 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 NET, Denial of Service, #CVE-2026-26130 (High) https://dailycve.com/net-denial-of-service-cve-2026-26130-high/

    Post summary

    The post announces a new high‑severity CVE-2026-26130 affecting NET with a denial‑of‑service vulnerability, without indicating exploits or patches.

    0000022
    167 followersView on X
  • VulnersHub@VulnersHub
    General

    CVE-2026-26130 http://ASP.NET Core Denial of Service Vulnerability http://dlvr.it/TRPv6z

    Post summary

    A brief notice cites CVE-2026-26130 as an ASP.NET Core denial‑of‑service flaw, but contains no actionable details or evidence of exploitation.

    0000014
    4 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftasp.net_core---

Explore more