CVE Vulnerabilities

CVE-2026-26171

Uncontrolled Resource Consumption

Published: Apr 14, 2026 | Modified: May 07, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.

Weakness

The product does not properly control the allocation and maintenance of a limited resource.

Affected Software

NameVendorStart VersionEnd Version
.netMicrosoft10.0.0 (including)10.0.6 (excluding)
Red Hat Enterprise Linux 10RedHatdotnet10.0-0:10.0.106-1.el10_1*
Red Hat Enterprise Linux 10RedHatdotnet8.0-0:8.0.126-1.el10_1*
Red Hat Enterprise Linux 10RedHatdotnet9.0-0:9.0.116-1.el10_1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatdotnet9.0-0:9.0.116-1.el10_0*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatdotnet8.0-0:8.0.126-1.el10_0*
Red Hat Enterprise Linux 8RedHatdotnet8.0-0:8.0.126-1.el8_10*
Red Hat Enterprise Linux 8RedHatdotnet10.0-0:10.0.106-1.el8_10*
Red Hat Enterprise Linux 8RedHatdotnet9.0-0:9.0.116-1.el8_10*
Red Hat Enterprise Linux 9RedHatdotnet8.0-0:8.0.126-1.el9_7*
Red Hat Enterprise Linux 9RedHatdotnet10.0-0:10.0.106-1.el9_7*
Red Hat Enterprise Linux 9RedHatdotnet9.0-0:9.0.116-1.el9_7*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatdotnet8.0-0:8.0.126-1.el9_4*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatdotnet9.0-0:9.0.116-1.el9_6*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatdotnet8.0-0:8.0.126-1.el9_6*
Red Hat Hardened ImagesRedHatdotnet10-0-main-10.0.106-1.hum1*
Red Hat Hardened ImagesRedHatdotnet8-0-main-8.0.126-1.hum1*
Red Hat Hardened ImagesRedHatdotnet9-0-main-9.0.116-1.hum1*
Dotnet10Ubuntudevel*
Dotnet10Ubuntunoble*
Dotnet10Ubuntuquesting*
Dotnet10Ubunturesolute*
Dotnet10Ubuntuupstream*
Dotnet7Ubuntujammy*
Dotnet8Ubuntujammy*
Dotnet8Ubuntunoble*
Dotnet8Ubuntuquesting*
Dotnet8Ubuntuupstream*
Dotnet9Ubuntuquesting*
Dotnet9Ubuntuupstream*

Potential Mitigations

  • Mitigation of resource exhaustion attacks requires that the target system either:

  • The first of these solutions is an issue in itself though, since it may allow attackers to prevent the use of the system by a particular valid user. If the attacker impersonates the valid user, they may be able to prevent the user from accessing the server in question.

  • The second solution is simply difficult to effectively institute – and even when properly done, it does not provide a full solution. It simply makes the attack require more resources on the part of the attacker.

References