GHSA-v3f6-m9j2-437pMedium· 5.9▾ SunlitDuplicate Advisory: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This advisory has been withdrawn because it is a duplicate of GHSA-8cp2-47hg-mfgh. This link is maintained to preserve external references.
Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
Microsoft.AspNetCore.Server.IISIntegration >= 11.0.0-preview.1, < 11.0.0-rc.1Microsoft.AspNetCore.Server.IISIntegration >= 8.0.0, <= 8.0.30Microsoft.AspNetCore.Server.IISIntegration >= 9.0.0, <= 9.0.19Microsoft.AspNetCore.Server.IISIntegration >= 10.0.0, <= 10.0.11Upgrade to a patched release:
Microsoft.AspNetCore.Server.IISIntegration 11.0.0-rc.1Microsoft.AspNetCore.Server.IISIntegration 8.0.31Microsoft.AspNetCore.Server.IISIntegration 9.0.20Microsoft.AspNetCore.Server.IISIntegration 10.0.12Connected by shared product, vendor, weakness, or advisory.
CVE-2026-69304Medium· 5.9Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network.
GHSA-mqvm-gmc4-6rv2High· 8.8Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
GHSA-4qhr-qf46-fcrxHigh· 8.8Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
GHSA-q72m-f2r4-w4cwHigh· 8.8Duplicate Advisory: Microsoft Security Advisory CVE-2026-69522 – .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2026-8814Medium· 5.3Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in maximum decompressed output size
CVE-2026-100208High· 7.5Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.