
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-69304 is a denial-of-service vulnerability caused by improper handling of highly compressed data (data amplification) in ASP.NET Core, classified under CWE-409. An unauthenticated remote attacker can exploit this flaw to render affected services unavailable by sending specially crafted, highly compressed payloads. Affected products include .NET 8.0 (before 8.0.31), .NET 9.0 (before 9.0.20), .NET 10.0 (before 10.0.12), ASP.NET Core 8.0, 9.0, 10.0, and 11.0 (before 11.0 RC1), Microsoft Visual Studio 2022 version 17.14 (before 17.14.40), and Visual Studio 2026 version 18.9 (before 18.9.3). The vulnerability was disclosed and patched on September 8, 2026, as part of Microsoft's September 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 5.9 (Medium) (Microsoft MSRC).
The root cause is CWE-409: Improper Handling of Highly Compressed Data (Data Amplification), commonly known as a "zip bomb" or decompression bomb attack. When ASP.NET Core processes incoming compressed request data, it fails to adequately limit the expansion ratio or resource consumption during decompression, allowing a small compressed payload to expand into a disproportionately large amount of data in memory. This attack vector is network-based, requires no authentication, no user interaction, and no special privileges, though the attack complexity is rated High, suggesting that specific conditions or timing may be required to reliably trigger the denial-of-service condition (Microsoft MSRC, Feedly). No public proof-of-concept code has been identified at this time.
Successful exploitation results in a denial-of-service condition, causing the targeted ASP.NET Core application or service to become unavailable. The impact is limited to availability — there is no confidentiality or integrity impact, meaning attackers cannot access or modify data through this vulnerability alone. Affected deployments include web APIs, web applications, and services built on .NET 8.0, 9.0, 10.0, and ASP.NET Core 8.0 through 11.0, potentially disrupting business-critical services for the duration of the attack (Microsoft MSRC).
As of the disclosure date, there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been identified (Feedly). The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The NVD SSVC assessment classifies exploitation as "none" and the technical impact as "partial." The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The High attack complexity rating further reduces the likelihood of widespread opportunistic exploitation.
Microsoft has released patches addressing this vulnerability as part of the September 2026 Patch Tuesday update cycle. Organizations should update to the following fixed versions: .NET 8.0.31, .NET 9.0.20, .NET 10.0.12, ASP.NET Core 11.0 RC1 or later, Visual Studio 2022 version 17.14.40, and Visual Studio 2026 version 18.9.3. As interim mitigations, administrators should monitor network traffic for unusual patterns of highly compressed data requests and consider implementing rate limiting on compressed data uploads and decompression operations (Microsoft MSRC, .NET Blog).
The vulnerability was covered as part of broader September 2026 Patch Tuesday roundups by BleepingComputer and the Zero Day Initiative, which noted it among the 96+ flaws addressed in that cycle (BleepingComputer, ZDI). Rapid7 also included it in their Patch Tuesday analysis (Rapid7). Community reaction has been measured given the Medium severity rating and absence of active exploitation.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."