mediumCVSS 5.9Vulnerability

CVE-2026-69304

# Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability ## Executive summary Microsoft is releasing this security advisory to provide information about a vulnerability in ASP.NET Core IIS out-of-process hosting and request decompression. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. The IIS Middleware for ASP.NET Core did not properly constrain decompression of certain types of request, leading to excess memory consumption and a Denial of Service. ## Announcement Announcement for this issue can be found at https://github.com/dotnet/announcements/issues/443 ## CVSS Details - **Version:** 3.1 - **Severity:** Medium - **Score:** 5.9 - **Vector:** `CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H` - **Weakness:** CWE-409 (Improper Handling of Highly Compressed Data (Data Amplification)) ## Affected Platforms - **Platforms:** Windows / IIS out-of-process - **Architectures:** All ## <a name="affected-packages"></a>Affected Packages The vulnerability affects any Microsoft .NET project if it uses any of affected package versions listed below ### <a name=".NET 11 RC1"></a>.NET 11 RC1 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.AspNetCore.Server.IISIntegration](https://www.nuget.org/packages/Microsoft.AspNetCore.Server.IISIntegration) | >= 11.0.0-preview.1, < 11.0.0-rc.1 | 11.0.0-rc.1 ### <a name=".NET 10"></a>.NET 10 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.AspNetCore.Server.IISIntegration](https://www.nuget.org/packages/Microsoft.AspNetCore.Server.IISIntegration) | >= 10.0.0, <= 10.0.11 | 10.0.12 ### <a name=".NET 9"></a>.NET 9 Package name | Affected version | Patched version ------------ | ---------------- | ------------------------- [Microsoft.AspNetCore.Server.IISIntegration](https://www.nuget.org

Properties

severity
medium
summary
Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerability
epss_score
0.00768
cvss_score
5.9
ghsa_published
2026-09-09T16:04:11Z
source_url
https://github.com/advisories/GHSA-8cp2-47hg-mfgh
ghsa_updated
2026-09-09T16:04:12Z
ghsa_id
GHSA-8cp2-47hg-mfgh
cve_id
CVE-2026-69304
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
false
epss_percentile
0.53413

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]nuget/Microsoft.AspNetCore.Server.IISIntegration

AFFECTS (1)

[Software]nuget/Microsoft.AspNetCore.Server.IISIntegration

HAS_WEAKNESS (1)

[Weakness]Improper Handling of Highly Compressed Data (Data Amplification)

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-69304 (CVSS 5.9) — Ninja Signal Threat Intelligence | Ninja Signal