CVE-2018-8409: Microsoft .net Core

High severity, CVSS 7.5. EPSS: 6.6% chance of exploitation in the next 30 days.

A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.

Affected products

  • Microsoft .net Core: from 2.1, before 2.1.4 (fixed in 2.1.4)
  • Microsoft ASP.NET Core: from 2.1, before 2.1.4 (fixed in 2.1.4)
  • Microsoft System.io.pipelines: version 4.5.0 only

Published 2018-09-13. Last modified 2026-06-17.