Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-45591

ASP.NET Core SignalR and Blazor Server: deeply nested MessagePack arrays cause denial of service

Technology

.NET

CVSS Score

7.5 / 10.0

Affected Versions

ASP.NET Core 8, 9 and 10 before the June 2026 releases

Upstream Fix

8.0.28; 9.0.17; 10.0.9

Published

June 9, 2026

OSSeva Coverage

Fixed upstream

Description

The MessagePack hub protocol used by SignalR and Blazor Server lets an unauthenticated attacker send deeply nested MessagePack arrays that cause a stack overflow and a denial of service. CVSS is Microsoft's score as the CNA.

Upstream record: NVD · CVE.org

Is your .NET deployment affected?

If you're running ASP.NET Core 8, 9 and 10 before the June 2026 releases, you need this patch. Book a discovery call to get covered.