USN-6427-1
Not scored
dotnet6, dotnet7 vulnerability
It was discovered that the .NET Kestrel web server did not properly handle HTTP/2 requests. A remote attacker could possibly use this issue to cause a denial of service.
Exploit probability
Not scored
Published
October 10, 2023
Required by
Not available
Last source change
April 27, 2026
02 / AFFECTED SOFTWARE
Affected packages
11 explicit affected versions
6 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
USN-6427-1
View original source
It was discovered that the .NET Kestrel web server did not properly handle HTTP/2 requests. A remote attacker could possibly use this issue to cause a denial of service.
05 / REFERENCES