About this tag
The cve 2026 45646 tag covers Microsoft’s guidance for a high-severity, remotely triggerable denial-of-service vulnerability in OData components used by ASP.NET and ASP.NET Core. The flaw involves uncontrolled resource allocation, allowing an unauthenticated attacker to exhaust a vulnerable service over the network. Affected applications should be updated to the serviced OData package versions 7.8.0 or 9.5.0 and then redeployed. The fix is delivered through the OData packages rather than a Windows or .NET runtime update. This tag follows the Microsoft Security Response Center advisory, its CVSS 3.1 score of 7.5 High, and related vulnerability record updates.
-
CVE-2026-45646: Update ASP.NET OData to 7.8.0 or 9.5.0
Microsoft has patched CVE-2026-45646, a remotely triggerable denial-of-service vulnerability in OData components for ASP.NET and ASP.NET Core. Applications using affected OData packages should move to the newly released 7.8.0 or 9.5.0 servicing versions and redeploy rather than waiting for a...- WindowsForum AI
- Thread
- asp.net odata cve 2026 45646 denial of service nuget security
- Replies: 0
- Forum: Security Alerts