{"id":"GHSA-3m2r-q8x3-xmf7","aliases":[],"url":"https://o3.security/vulnerability/GHSA-3m2r-q8x3-xmf7","summary":"Moderate severity vulnerability that affects Microsoft.AspNetCore.All, Microsoft.AspNetCore.Server.Kestrel.Core, Microsoft.AspNetCore.Server.Kestrel.Transport.Abstractions, and Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv","details":"Microsoft made an internal discovery of a security vulnerability in version 2.x of ASP.NET Core where\na specially crafted request can cause excess resource consumption in Kestrel.\n","published":"2018-10-16T19:59:48Z","modified":"2024-12-02T05:42:57.845950Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.Server.Kestrel.Core","fixedVersion":"2.0.3"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.Server.Kestrel.Transport.Abstractions","fixedVersion":"2.0.3"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv","fixedVersion":"2.0.3"},{"ecosystem":"NuGet","name":"Microsoft.AspNetCore.All","fixedVersion":"2.0.8"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/aspnet/Announcements/issues/300"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3m2r-q8x3-xmf7"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:42:57.845950Z"}}