ghsa-vh8f-65qg-3m8j
CVSS 7.5 osv_nuget
Description
### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-4vgm-c2wm-63mw. This link is maintained to preserve external references. ### Original Description Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
References
Linked Vulnerabilities
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "<= 8.0.24",
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-vh8f-65qg-3m8j/GHSA-vh8f-65qg-3m8j.json"
},
"package": {
"ecosystem": "NuGet",
"name": "Microsoft.AspNetCore.App.Runtime.linux-arm",
"purl": "pkg:nuget/Microsoft.AspNetCore.App.Runtime.linux-arm"
},
"ranges": [
{
"events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.0.25"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"8.0.0",
"8.0.1",
"8.0.10",
"8.0.11",
"8.0.12",
"8.0.13",
"8.0.14",
"8.0.15",
"8.0.16",
"8.0.17",
"8.0.18",
"8.0.19",
"8.0.2",
"8.0.20",
"8.0.21",
"8.0.22",
"8.0.23",
"8.0.24",
"8.0.3",
"8.0.4",
"8.0.5",
"8.0.6",
"8.0.7",
"8.0.8"
]
}
],
"database_specific": {
"cwe_ids": [
"CWE-770"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-11T19:53:57Z",
"nvd_published_at": "2026-03-10T18:18:42Z",
"severity": "HIGH"
},
"details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-4vgm-c2wm-63mw. This link is maintained to preserve external references.\n\n### Original Description\nAllocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.",
"id": "GHSA-vh8f-65qg-3m8j",
"modified": "2026-09-10T03:51:01.201117872Z",
"published": "2026-03-10T18:31:21Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-26130"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26130"
}
],
"schema_version": "1.9.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "Duplicate Advisory: .NET Denial of Service Vulnerability",
"withdrawn": "2026-03-11T19:53:57Z"
}