Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 01 May 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote DoS via Crafted QUIC Packet in ASP.NET Core Kestrel |
Wed, 22 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 15 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial of Service via Crafted QUIC Packet in ASP.NET Core Kestrel |
Tue, 14 Apr 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft .net
|
|
| CPEs | cpe:2.3:a:microsoft:.net:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft .net
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Denial of Service via Crafted QUIC Packet in ASP.NET Core Kestrel |
Tue, 24 Mar 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
cvssV3_1
|
Fri, 20 Mar 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft aspnetcore |
|
| Vendors & Products |
Microsoft
Microsoft aspnetcore |
Thu, 19 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ASP.NET Core Kestrel in Microsoft .NET 8.0 before 8.0.22 and .NET 9.0 before 9.0.11 allows a remote attacker to cause excessive CPU consumption by sending a crafted QUIC packet, because of an incorrect exit condition for HTTP/3 Encoder/Decoder stream processing. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-29T14:34:11.558Z
Reserved: 2026-02-04T00:00:00.000Z
Link: CVE-2026-25667
Updated: 2026-03-24T01:32:53.058Z
Status : Modified
Published: 2026-03-19T19:16:19.880
Modified: 2026-04-22T17:16:34.337
Link: CVE-2026-25667
No data.
OpenCVE Enrichment
Updated: 2026-05-01T05:45:10Z