CVE-2023-38180
HIGH.NET Denial of Service Vulnerability
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Blast Radius
Microsoft.AspNetCore.App.Runtime.win-arm64.NETMicrosoft.AspNetCore.App.Runtime.win-x64.NETMicrosoft.AspNetCore.App.Runtime.win-x86.NETMicrosoft.AspNetCore.Server.Kestrel.Transport.Libuv.NETMicrosoft.AspNetCore.App.Runtime.win-arm64.NETMicrosoft.AspNetCore.App.Runtime.win-x64.NETMicrosoft.AspNetCore.App.Runtime.win-x86.NETMicrosoft.AspNetCore.Server.Kestrel.Transport.Libuv+1 moreReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects NuGet packages — download data is not available via public APIs for these ecosystems.
Description
.NET and Visual Studio Denial of Service Vulnerability
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| .NETNuGet | Microsoft.AspNetCore.App.Runtime.win-arm64 | ≥ 7.0.0&&< 7.0.10 | 7.0.10 |
| .NETNuGet | Microsoft.AspNetCore.App.Runtime.win-x64 | ≥ 7.0.0&&< 7.0.10 | 7.0.10 |
| .NETNuGet | Microsoft.AspNetCore.App.Runtime.win-x86 | ≥ 7.0.0&&< 7.0.10 | 7.0.10 |
| .NETNuGet | Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv | ≥ 6.0.0&&< 6.0.21 | 6.0.21 |
| .NETNuGet | Microsoft.AspNetCore.App.Runtime.win-arm64 | ≥ 6.0.0&&< 6.0.21 | 6.0.21 |
| .NETNuGet | Microsoft.AspNetCore.App.Runtime.win-x64 | ≥ 6.0.0&&< 6.0.21 | 6.0.21 |
Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Frequently Asked Questions
Is CVE-2023-38180 in your stack?
O3 detects CVE-2023-38180 across NuGet dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.