CVE-2026-42899Disclosure(apple / .net)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple .net systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service over a network.

3.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • .net
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-05-12); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
.netlinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-05-12: 3Mentions · 2026-05-15: 1Mentions · 2026-05-18: 1PoC Mentioned / Linked · 2026-05-15: 1Patch / Workaround · 2026-05-12: 2Technical Details · 2026-05-12: 2Technical Details · 2026-05-15: 1Technical Details · 2026-05-18: 105-1205-1505-18
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
PoC
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-123
Disclosure1Patch2
2026-05-151
PoC1
2026-05-181
Disclosure1
Full discourse5 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High Severity - http://ASP.NET Core Denial of Service Vulnerability (CVE-2026-42899) Microsoft disclosed a high-severity http://ASP.NET Core vulnerability that may allow unauthenticated attackers to trigger a Denial of Service condition via an infinite loop caused by unreachable exit conditions. Affected versions: • .NET 8.0 ≤ 8.0.26 → fixed in 8.0.27 • .NET 9.0 ≤ 9.0.15 → fixed in 9.0.16 • .NET 10.0 ≤ 10.0.7 → fixed in 10.0.8 The issue impacts multiple http://ASP.NET Core runtime packages across Linux, Windows, and macOS platforms. 👉 Consider upgrading to the latest patched runtime versions during your next maintenance window. Ref: https://github.com/dotnet/aspnetcore/security/advisories/GHSA-9v76-4qcc-frgh

    Post summary

    The tweet announces a high severity ASP.NET Core Denial-of-Service vulnerability (CVE-2026-42899), details affected .NET versions, and directs users to upgrade to patched releases.

    0002097
    187 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 NET / ASPNET Core, Denial of Service (DoS), #CVE-2026-42899 (High) https://dailycve.com/net-aspnet-core-denial-of-service-dos-cve-2026-42899-high/

    Post summary

    The message announces a high‑severity Denial of Service vulnerability (CVE‑2026‑42899) in ASP.NET Core, pointing to a DailyCVE article for further details.

    0000053
    206 followersView on X
  • Israel@f1tym1
    PoC

    CVE-2026-42899 | Microsoft http://ASP.NET up to 5.1 infinite loop (Nessus ID 314680) https://ift.tt/Y7MwFgm A vulnerability was found in Microsoft http://ASP.NET up to 5.1 and classified as problematic. This vulnerability affects unknown code. The manipulatio…

    Post summary

    The post announces CVE‑2026‑42899 and provides a link likely containing a proof‑of‑concept, but gives no details on active exploitation, patches, or exploit code.

    0000039
    974 followersView on X
  • WindowsForum@windowsforum
    Patch

    🧨 CVE-2026-42899 is the ultimate “nothing personal, just outages” bug: an unauth DoS via an http://ASP.NET Core infinite loop. Important because cloud = uptime or doom. #Windows #Security https://windowsforum.com/threads/cve-2026-42899-patch-asp-net-core-infinite-loop-dos-in-net-8-9-10-important.417912/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #NetSecurity #AspNetCoreDos #Cve202642899 #Net8Patching https://t.co/fKKF0ysqyJ

    Post summary

    The post identifies an unauthenticated DoS vulnerability (CVE-2026-42899) in ASP.NET Core that causes an infinite loop and notes that a patch is available for .NET 8/9/10.

    0000036
    1.1K followersView on X
  • VulnersHub@VulnersHub
    Disclosure

    CVE-2026-42899 http://ASP.NET Core Denial of Service Vulnerability http://dlvr.it/TSVrMF

    Post summary

    The tweet announces the existence of a new ASP.NET Core Denial of Service vulnerability (CVE-2026-42899) without providing detailed technical information, proof of concept, or exploitation evidence.

    0000021
    6 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
OSlinuxlinux_kernel---
Appmicrosoft.net---
OSmicrosoftwindows---

Explore more