Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-38180

ASP.NET Core Kestrel: failure to disconnect a malicious client causes denial of service

Technology

.NET

CVSS Score

7.5 / 10.0

Affected Versions

.NET 7.0 and 6.0 before the August 2023 releases; ASP.NET Core 2.1 packages

Upstream Fix

7.0.10; 6.0.21

Published

August 8, 2023

OSSeva Coverage

Fixed upstream

Description

On detecting a potentially malicious client, Kestrel sometimes failed to disconnect it, resulting in denial of service. CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 9 August 2023. Microsoft notes that a reverse proxy or web application firewall with its own HTTP mitigations may mitigate it. CVSS is Microsoft's score as the CNA.

Upstream record: NVD · CVE.org

Is your .NET deployment affected?

If you're running .NET 7.0 and 6.0 before the August 2023 releases; ASP.NET Core 2.1 packages, you need this patch. Book a discovery call to get covered.