CVE-2021-26423

Related Vulnerabilities: CVE-2021-26423  

An infinite loop error was found in ASP.NET when processing WebSocket frames. The exploitation of this issue can cause high CPU resource consumption. The highest threat from this vulnerability is to system availability.

Description

An infinite loop error was found in ASP.NET when processing WebSocket frames. The exploitation of this issue can cause high CPU resource consumption. The highest threat from this vulnerability is to system availability.

Additional Information

  • Bugzilla 1990295: CVE-2021-26423 dotnet: ASP.NET Core WebSocket frame processing DoS
  • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
  • FAQ: Frequently asked questions about CVE-2021-26423