CVE-2018-8409 describes a denial of service vulnerability within System.IO.Pipelines, impacting .NET Core 2.1, ASP.NET Core 2.1, and System.IO.Pipelines. This vulnerability carries a CVSS score of 7.5 (HIGH), indicating it can be exploited remotely with low complexity, requiring no user interaction, to achieve a complete denial of service. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has received notable community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.1, < 2.1.4CPE matchmatch criteria | cpe:2.3:a:microsoft:.net_core:*:*:*:*:*:*:*:* | ||
>= 2.1, < 2.1.4CPE matchmatch criteria | cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:* | ||
4.5.0CPE matchmatch criteria | cpe:2.3:a:microsoft:system.io.pipelines:4.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
Oct 16, 2018System.IO.Pipelines Denial of Service
Sep 11, 2018NET: Resource loop in ReadAsync when it is being cancelled while producer allocates memory using GetMemory
Sep 11, 2018