A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application.
The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests.
Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2252 | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. |
Github GHSA |
GHSA-3w5p-jhp5-c29q | .NET Core & .NET Framework Denial of Service Vulnerability |
Wed, 19 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. | A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against a .NET Core or .NET Framework web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the .NET Core or .NET Framework application. The update addresses the vulnerability by correcting how the .NET Core or .NET Framework web application handles web requests. |
| Title | dotnet: Denial of service via untrusted input | .NET Core & .NET Framework Denial of Service Vulnerability |
| CPEs | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:*:sp2:*:*:*:*:*:* cpe:2.3:a:microsoft:.net_framework:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:powershell_core:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* |
|
| References |
|
Subscriptions
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-19T16:34:04.566Z
Reserved: 2019-11-04T00:00:00.000Z
Link: CVE-2020-1108
No data.
Status : Modified
Published: 2020-05-21T23:15:14.867
Modified: 2026-08-19T17:17:18.240
Link: CVE-2020-1108
OpenCVE Enrichment
No data.
-
CWE-190
Integer Overflow or Wraparound
-
CWE-20
Improper Input Validation
- NVD-CWE-noinfo
EUVD
Github GHSA