CVE-2026-69304
C# vulnerability analysis and mitigation

Overview

CVE-2026-69304 is a denial-of-service vulnerability caused by improper handling of highly compressed data (data amplification) in ASP.NET Core, classified under CWE-409. An unauthenticated remote attacker can exploit this flaw to render affected services unavailable by sending specially crafted, highly compressed payloads. Affected products include .NET 8.0 (before 8.0.31), .NET 9.0 (before 9.0.20), .NET 10.0 (before 10.0.12), ASP.NET Core 8.0, 9.0, 10.0, and 11.0 (before 11.0 RC1), Microsoft Visual Studio 2022 version 17.14 (before 17.14.40), and Visual Studio 2026 version 18.9 (before 18.9.3). The vulnerability was disclosed and patched on September 8, 2026, as part of Microsoft's September 2026 Patch Tuesday. It carries a CVSS v3.1 base score of 5.9 (Medium) (Microsoft MSRC).

Technical details

The root cause is CWE-409: Improper Handling of Highly Compressed Data (Data Amplification), commonly known as a "zip bomb" or decompression bomb attack. When ASP.NET Core processes incoming compressed request data, it fails to adequately limit the expansion ratio or resource consumption during decompression, allowing a small compressed payload to expand into a disproportionately large amount of data in memory. This attack vector is network-based, requires no authentication, no user interaction, and no special privileges, though the attack complexity is rated High, suggesting that specific conditions or timing may be required to reliably trigger the denial-of-service condition (Microsoft MSRC, Feedly). No public proof-of-concept code has been identified at this time.

Impact

Successful exploitation results in a denial-of-service condition, causing the targeted ASP.NET Core application or service to become unavailable. The impact is limited to availability — there is no confidentiality or integrity impact, meaning attackers cannot access or modify data through this vulnerability alone. Affected deployments include web APIs, web applications, and services built on .NET 8.0, 9.0, 10.0, and ASP.NET Core 8.0 through 11.0, potentially disrupting business-critical services for the duration of the attack (Microsoft MSRC).

Exploitability

As of the disclosure date, there is no evidence of active in-the-wild exploitation and no public proof-of-concept exploit has been identified (Feedly). The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The NVD SSVC assessment classifies exploitation as "none" and the technical impact as "partial." The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The High attack complexity rating further reduces the likelihood of widespread opportunistic exploitation.

Mitigation and workarounds

Microsoft has released patches addressing this vulnerability as part of the September 2026 Patch Tuesday update cycle. Organizations should update to the following fixed versions: .NET 8.0.31, .NET 9.0.20, .NET 10.0.12, ASP.NET Core 11.0 RC1 or later, Visual Studio 2022 version 17.14.40, and Visual Studio 2026 version 18.9.3. As interim mitigations, administrators should monitor network traffic for unusual patterns of highly compressed data requests and consider implementing rate limiting on compressed data uploads and decompression operations (Microsoft MSRC, .NET Blog).

Community reactions

The vulnerability was covered as part of broader September 2026 Patch Tuesday roundups by BleepingComputer and the Zero Day Initiative, which noted it among the 96+ flaws addressed in that cycle (BleepingComputer, ZDI). Rapid7 also included it in their Patch Tuesday analysis (Rapid7). Community reaction has been measured given the Medium severity rating and absence of active exploitation.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

devel

dotnet10

Not Affected

jammy

dotnet6

Not Affected

noble

dotnet8

Not Affected

resolute

dotnet10

Not Affected

Alpine

Fixed

edge

dotnet10-runtime: 10.0.12-r0, 8.0.31-r0, 9.0.20-r0

Fixed

SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71328HIGH8.8
  • C# logoC#
  • Microsoft.DiaSymReader.Native
NoYesSep 08, 2026
CVE-2026-69522HIGH8.8
  • C# logoC#
  • dotnet10-runtime
NoYesSep 08, 2026
CVE-2026-69439HIGH8.8
  • C# logoC#
  • dotnet10-runtime
NoYesSep 08, 2026
CVE-2026-69304MEDIUM5.9
  • C# logoC#
  • dotnet9-runtime
NoYesSep 08, 2026
GHSA-cvhv-g4rq-3hmwLOW3.3
  • C# logoC#
  • Magick.NET-Q8-OpenMP-arm64
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management