A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application.
The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application. The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests. |
| Title | dotnet: Denial of service due to infinite loop | ASP.NET Core Denial of Service Vulnerability |
| CPEs | cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:* | |
| References |
|
Status: PUBLISHED
Assigner: microsoft
Published: 2020-05-21T22:53:28.000Z
Updated: 2026-08-19T16:34:12.596Z
Reserved: 2019-11-04T00:00:00.000Z
Link: CVE-2020-1161
No data.
Status : Modified
Published: 2020-05-21T23:15:17.603
Modified: 2026-08-19T17:17:28.160
Link: CVE-2020-1161