Threat Advisory

Core Flaw Lets Attackers Consume Excess Memory

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A vulnerability affecting Microsoft.AspNetCore.Server.IISIntegration versions >= 11.0.0-preview.1, < 11.0.0-rc.1 affecting Microsoft.AspNetCore.Server.IISIntegration versions >= 9.0.0, <= 9.0.19 in ASP.NET Core IIS out-of-process hosting and request decompression, identified as CVE-2026-69304 with a CVSS score of 5.9, allows an attacker to cause excess memory consumption leading to a Denial of Service. The flaw type is CWE-409 (Improper Handling of Highly Compressed Data (Data Amplification)) and the attack vector is network-based. This vulnerability affects any Microsoft.NET project that uses affected package versions of Microsoft.AspNetCore.Server.IISIntegration, specifically those in the version range >= 8.0.0, <= 8.0.30, which can be patched with version 8.0.31. Business impact includes potential data loss and system downtime due to the Denial of Service attack.

RECOMMENDATION:

We recommend you to update Microsoft.AspNetCore.Server.IISIntegration to version 11.0.0-rc.1, 8.0.31, 9.0.20, or 10.0.12.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A vulnerability affecting Microsoft.AspNetCore.Server.IISIntegration versions >= 11.0.0-preview.1, < 11.0.0-rc.1 affecting Microsoft.AspNetCore.Server.IISIntegration versions >= 9.0.0, <= 9.0.19 in ASP.NET Core IIS out-of-process hosting and request decompression, identified as CVE-2026-69304 with a CVSS score of 5.9, allows an attacker to cause excess memory consumption leading to a Denial of Service. The flaw type is CWE-409 (Improper Handling of Highly Compressed Data (Data Amplification)) and the attack vector is network-based. This vulnerability affects any Microsoft.NET project that uses affected package versions of Microsoft.AspNetCore.Server.IISIntegration, specifically those in the version range >= 8.0.0, <= 8.0.30, which can be patched with version 8.0.31. Business impact includes potential data loss and system downtime due to the Denial of Service attack.

RECOMMENDATION:

We recommend you to update Microsoft.AspNetCore.Server.IISIntegration to version 11.0.0-rc.1, 8.0.31, 9.0.20, or 10.0.12.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu