CVE-2026-69304
# Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability ## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core IIS out-of-process hosting and request decompression. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. The IIS Middleware for ASP.NET Core did not properly constrain decompression of certain types of request, leading to excess memory consumption and a Denial of Service. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/443 ## CVSS Details - **Version:** 3.1 - **Severity:** Medium - **Score:** 5.9 - **Vector:** `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H` - **Weakness:** CWE-409 (Improper Handling of Highly Compressed Data (Data Amplification)) ## Affected Platforms - **Platforms:** Windows / IIS out-of-process - **Architectures:** All ## <a name="affected-packages"></a>Affected Packages The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below ### <a name=".NET 11 RC1"></a>.NET 11 RC1 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.AspNetCore.Server.IISIntegration](https://www.nuget.org/packages/Microsoft.AspNetCore.Server.IISIntegration) | >= 11.0.0-preview.1, < 11.0.0-rc.1 | 11.0.0-rc.1 ### <a name=".NET 10"></a>.NET 10 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.AspNetCore.Server.IISIntegration](https://www.nuget.org/packages/Microsoft.AspNetCore.Server.IISIntegration) | >= 10.0.0, <= 10.0.11 | 10.0.12 ### <a name=".NET 9"></a>.NET 9 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.AspNetCore.Server.IISIntegration](https://www.nuget.org
Properties
- severity
- medium
- summary
- Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
- epss_score
- 0.00768
- cvss_score
- 5.9
- ghsa_published
- 2026-09-09T16:04:11Z
- source_url
- https://github.com/advisories/GHSA-8cp2-47hg-mfgh
- ghsa_updated
- 2026-09-09T16:04:12Z
- ghsa_id
- GHSA-8cp2-47hg-mfgh
- cve_id
- CVE-2026-69304
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- is_ghsa_only
- false
- epss_percentile
- 0.53413
Related Entities (5)
ENRICHED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph