A vulnerability affecting Microsoft.AspNetCore.Server.IISIntegration versions >= 11.0.0-preview.1, < 11.0.0-rc.1 affecting Microsoft.AspNetCore.Server.IISIntegration versions >= 9.0.0, <= 9.0.19 in ASP.NET Core IIS out-of-process hosting and request decompression, identified as CVE-2026-69304 with a CVSS score of 5.9, allows an attacker to cause excess memory consumption leading to a Denial of Service. The flaw type is CWE-409 (Improper Handling of Highly Compressed Data (Data Amplification)) and the attack vector is network-based. This vulnerability affects any Microsoft.NET project that uses affected package versions of Microsoft.AspNetCore.Server.IISIntegration, specifically those in the version range >= 8.0.0, <= 8.0.30, which can be patched with version 8.0.31. Business impact includes potential data loss and system downtime due to the Denial of Service attack.
We recommend you to update Microsoft.AspNetCore.Server.IISIntegration to version 11.0.0-rc.1, 8.0.31, 9.0.20, or 10.0.12.[/subscribe_to_unlock_form]
A vulnerability affecting Microsoft.AspNetCore.Server.IISIntegration versions >= 11.0.0-preview.1, < 11.0.0-rc.1 affecting Microsoft.AspNetCore.Server.IISIntegration versions >= 9.0.0, <= 9.0.19 in ASP.NET Core IIS out-of-process hosting and request decompression, identified as CVE-2026-69304 with a CVSS score of 5.9, allows an attacker to cause excess memory consumption leading to a Denial of Service. The flaw type is CWE-409 (Improper Handling of Highly Compressed Data (Data Amplification)) and the attack vector is network-based. This vulnerability affects any Microsoft.NET project that uses affected package versions of Microsoft.AspNetCore.Server.IISIntegration, specifically those in the version range >= 8.0.0, <= 8.0.30, which can be patched with version 8.0.31. Business impact includes potential data loss and system downtime due to the Denial of Service attack.
We recommend you to update Microsoft.AspNetCore.Server.IISIntegration to version 11.0.0-rc.1, 8.0.31, 9.0.20, or 10.0.12.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]