TopVuln

High-risk vulnerability digests

CVE-2026-25667

  • HIGH

BIT-DOTNET-2026-25667

Details

CVSS v3
7.5
NVD published
2026-03-19 19:16:19
EPSS
2.4% probability · 85.1th percentile — 2026-04-17
Affected versions
cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:*
Summary
ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing.
Remediation
Not available in our cache.
Exploit info
https://github.com/IsaJafarov/Kestrel-DoS

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.