VDB

CVE-2026-69304

CVE-2026-69304 PUBLISHED CVSS 5.9 MEDIUM

Reported by microsoft · Published September 8, 2026

Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.

Risk Scores

CVSS 3.1
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

Affected Products

VendorProductVersions
Microsoft.NET 10.010.0.0
Microsoft.NET 8.08.0.0
Microsoft.NET 9.09.0.0
MicrosoftASP.NET Core 10.010.0
MicrosoftASP.NET Core 11.011.0
MicrosoftASP.NET Core 8.08.0
MicrosoftASP.NET Core 9.09.0
MicrosoftMicrosoft Visual Studio 2022 version 17.1417.14.0
MicrosoftMicrosoft Visual Studio 2026 version 18.918.9.0
microsoft.net8.0.0, 10.0.0, 9.0.0
Microsoft.NET 8.08.0.0
microsoftasp.net_core10.0, 8.0, 11.0
Microsoft.NET 9.09.0.0
MicrosoftASP.NET Core 11.011.0
MicrosoftASP.NET Core 9.09.0
MicrosoftASP.NET Core 10.010.0
Microsoft.NET 10.010.0.0
microsoftvisual_studio_202618.9.0
MicrosoftMicrosoft Visual Studio 2026 version 18.918.9.0
microsoftvisual_studio_202217.14.0

…and 2 more

Timeline

  • Sep 8, 2026 CVE Published
  • Sep 8, 2026 CVE Updated
  • Sep 9, 2026 Coalition ESS Score
  • Sep 9, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›