Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38843
HistoryJan 12, 2023 - 4:11 a.m.

Denial Of Service (DoS)

2023-01-1204:11:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22
microsoft
.net core
runtime
vulnerable
dos
datacontractserializer
recursive collections
stack overflow
application crash

EPSS

0.001

Percentile

47.9%

microsoft.netcore.app.runtime.* packages are vulnerable to Denial of Service (DoS) attacks. The vulnerability is due to the DataContractSerializer handling recursive collections, which allows a malicious user to cause a stack overflow which may result in a denial of service, resulting in an application crash.