CVE-2022-21986

Related Vulnerabilities: CVE-2022-21986  

A vulnerability was found in dotnet’s ASP.NET Core Krestel when pooling HTTP/2 and HTTP/3 headers. This flaw allows a remote, unauthenticated attacker to cause a denial of service.

Description

A vulnerability was found in dotnet’s ASP.NET Core Krestel when pooling HTTP/2 and HTTP/3 headers. This flaw allows a remote, unauthenticated attacker to cause a denial of service.

Additional Information

  • Bugzilla 2051490: CVE-2022-21986 dotnet: ASP.NET Core Krestel HTTP headers pooling denial of service
  • CWE-770: Allocation of Resources Without Limits or Throttling
  • FAQ: Frequently asked questions about CVE-2022-21986