ASP.NET Core and Visual Studio Denial of Service Vulnerability
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Oct 9, 2024
Package
Affected versions
>= 3.1.0, < 3.1.11
>= 5.0.0, < 5.0.2
Patched versions
3.1.11
5.0.2
>= 3.1.0, < 3.1.11
>= 5.0.0, < 5.0.2
3.1.11
5.0.2
>= 3.1.0, < 3.1.11
>= 5.0.0, < 5.0.2
3.1.11
5.0.2
>= 3.1.0, < 3.1.11
>= 5.0.0, < 5.0.2
3.1.11
5.0.2
>= 3.1.0, < 3.1.11
>= 5.0.0, < 5.0.2
3.1.11
5.0.2
>= 3.1.0, < 3.1.11
>= 5.0.0, < 5.0.2
3.1.11
5.0.2
Description
Published by the National Vulnerability Database
Jan 12, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Oct 24, 2022
Last updated
Oct 9, 2024
A denial-of-service vulnerability exists in the way Kestrel parses HTTP/2 requests. The security update addresses the vulnerability by fixing the way the Kestrel parses HTTP/2 requests. Users are advised to upgrade.
References