CVE-2024-21386: Microsoft ASP.NET Core

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

.NET Denial of Service Vulnerability

Affected products

  • Microsoft ASP.NET Core: from 6.0.0, before 6.0.27 (fixed in 6.0.27); from 7.0.0, before 7.0.16 (fixed in 7.0.16); from 8.0.0, before 8.0.2 (fixed in 8.0.2)
  • Microsoft Visual Studio 2022: from 17.4.0, before 17.4.16 (fixed in 17.4.16); from 17.6.0, before 17.6.12 (fixed in 17.6.12); from 17.8.0, before 17.8.7 (fixed in 17.8.7)

Published 2024-02-13. Last modified 2026-08-10.