{"id":"GHSA-vh8f-65qg-3m8j","summary":"Duplicate Advisory: .NET Denial of Service Vulnerability","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-4vgm-c2wm-63mw. This link is maintained to preserve external references.\n\n### Original Description\nAllocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.","modified":"2026-09-10T03:51:01.201117872Z","published":"2026-03-10T18:31:21Z","withdrawn":"2026-03-11T19:53:57Z","database_specific":{"nvd_published_at":"2026-03-10T18:18:42Z","cwe_ids":["CWE-770"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-11T19:53:57Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26130"},{"type":"WEB","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26130"}],"affected":[{"package":{"name":"Microsoft.AspNetCore.App.Runtime.linux-arm","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.AspNetCore.App.Runtime.linux-arm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.0.25"}]}],"versions":["8.0.0","8.0.1","8.0.10","8.0.11","8.0.12","8.0.13","8.0.14","8.0.15","8.0.16","8.0.17","8.0.18","8.0.19","8.0.2","8.0.20","8.0.21","8.0.22","8.0.23","8.0.24","8.0.3","8.0.4","8.0.5","8.0.6","8.0.7","8.0.8"],"database_specific":{"last_known_affected_version_range":"\u003c= 8.0.24","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-vh8f-65qg-3m8j/GHSA-vh8f-65qg-3m8j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}