
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26130 is a Denial of Service vulnerability in ASP.NET Core caused by allocation of resources without limits or throttling. A specially crafted message sent to a SignalR server can exhaust an internal buffer, causing the application to become unavailable. Affected versions include ASP.NET Core 8.0.0–8.0.24, 9.0.0–9.0.13, and 10.0.0–10.0.3, across all platforms and architectures. The vulnerability was disclosed on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Microsoft MSRC).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). Specifically, the vulnerability exists in ASP.NET Core's SignalR server component, where a specially crafted network message can cause an internal buffer to be exhausted without any imposed size or count restrictions. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity — making it trivially exploitable by any remote attacker who can reach a SignalR endpoint. No public proof-of-concept code has been identified at this time (GitHub Advisory, Microsoft MSRC).
Successful exploitation results in a Denial of Service condition, rendering the affected ASP.NET Core application unavailable to legitimate users. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability. Applications hosting SignalR endpoints are at highest risk, and sustained exploitation could cause prolonged outages without any attacker foothold on the underlying system (GitHub Advisory, Microsoft MSRC).
/signalr or hub-specific URLs.wss://target/hub).dotnet.exe or dotnet on Linux) without a corresponding increase in legitimate user traffic; application pool recycling or process crashes correlated with inbound SignalR traffic spikes.Microsoft released patched versions on March 10, 2026: update to ASP.NET Core 8.0.25, 9.0.14, or 10.0.4 as appropriate. Self-contained applications targeting affected versions must be recompiled and redeployed after updating the SDK. As interim controls, implement network-level rate limiting and connection throttling in front of SignalR endpoints (e.g., via reverse proxy or WAF rules), and monitor for unusual resource consumption patterns. Visual Studio users will be prompted to update, which will also update the .NET SDK (GitHub Advisory, Microsoft MSRC, .NET Blog).
The vulnerability was covered as part of broader March 2026 Patch Tuesday reporting by outlets including BleepingComputer, CyberSecurityNews, Rapid7, and Zero Day Initiative, which noted it among 79 vulnerabilities addressed that month. Sophos and Lansweeper also published Patch Tuesday summaries referencing this CVE. Red Hat, Ubuntu, AlmaLinux, and Rocky Linux all issued corresponding advisories and errata for their .NET packages. The security community noted the vulnerability was credited to researcher Bartłomiej Dach (GitHub Advisory, .NET Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."